GFI Software

Welcome to the GFI Software community forum! For support please open a ticket from https://support.gfi.com.

Home » GFI User Forums » Kerio Control » Kerio Control - Performance problem - Snort 3
Kerio Control - Performance problem - Snort 3 [message #149606] Thu, 15 April 2021 10:54 Go to next message
walterzanella is currently offline  walterzanella
Messages: 37
Registered: March 2013
Location: Italia

Hi everyone,
I wanted to know if any updates will be released, to solve the performance problems with 1Gbit broadband, which starts to be frequent in our installations. I guess solvable with the adoption of snort 3.
Using HyperV we can hardly exceed 300 / 400Mbits.
Thank you.

[Updated on: Thu, 15 April 2021 10:54]

Report message to a moderator

Re: Kerio Control - Performance problem - Snort 3 [message #149676 is a reply to message #149606] Fri, 23 April 2021 19:18 Go to previous messageGo to next message
robinbateman is currently offline  robinbateman
Messages: 225
Registered: April 2012
Location: Oxford(ish) UK

I have been waiting on this for a year now

After extensive testing, engineers confirmed there was an issue that would be fixed in the next release but STILL waiting

Clients so unhappy that their firewalls cannot provide the correct throughput for their expensive high performance based lines (I have a few)


Robin Bateman
One Red Mouse
Blog: http://bit.ly/OWjcGL
Re: Kerio Control - Performance problem - Snort 3 [message #149701 is a reply to message #149676] Tue, 04 May 2021 11:05 Go to previous messageGo to next message
robinbateman is currently offline  robinbateman
Messages: 225
Registered: April 2012
Location: Oxford(ish) UK

Is this speed issue fixed with release 9.3.6?

Robin Bateman
One Red Mouse
Blog: http://bit.ly/OWjcGL
Re: Kerio Control - Performance problem - Snort 3 [message #149704 is a reply to message #149701] Wed, 05 May 2021 12:07 Go to previous messageGo to next message
mzaidi is currently offline  mzaidi
Messages: 109
Registered: April 2021
The Kerio Control version 9.3.6 is a minor update release and the Performance issues are being tracked for the major update release.

For the issues that are fixed in 9.3.6, please refer to the release notes: https://support.keriocontrol.gfi.com/hc/en-us/articles/36002 1036560-Kerio-Control-9-3-6-Release-Notes
Re: Kerio Control - Performance problem - Snort 3 [message #149705 is a reply to message #149606] Wed, 05 May 2021 16:34 Go to previous messageGo to next message
robinbateman is currently offline  robinbateman
Messages: 225
Registered: April 2012
Location: Oxford(ish) UK

So when is this due as it has been over a year since it was reported on ticket #2160727?

Robin Bateman
One Red Mouse
Blog: http://bit.ly/OWjcGL
Re: Kerio Control - Performance problem - Snort 3 [message #153820 is a reply to message #149705] Tue, 21 February 2023 08:42 Go to previous messageGo to next message
cto is currently offline  cto
Messages: 1
Registered: February 2023
Are there any news to this matter. Having 500Mbit symmetrical internet connection and Kerio is not able to provide more than 100Mbits.
If Kerio still did not resolve this then what would be a good alternative?
Re: Kerio Control - Performance problem - Snort 3 [message #153838 is a reply to message #153820] Thu, 23 February 2023 13:44 Go to previous messageGo to next message
tverweij is currently offline  tverweij
Messages: 72
Registered: March 2010
Location: Curacao
It is now almost 2 years after the initial message in this topic - still no Snort3, and the IPS botteneck is growing as internet lines are becoming faster.
I heard they were working on it, but that is also a few months ago.

But this is not the only thing that worries me. Kerio is getting out of usable state because of lack of updates.
I mean: UEFI support (security and new hardware). Snort3 support (performance). AES-NI support (hardware acceleration). Traffic prioritizing (the next step in QOS). Android 12+ VPN support.
Kerio is loosing terrain each month that those things are not implemented, and there will be a point that even I have to decide to look for another firewall (I am working with kerio since about 2004, maybe earlier).

Update: I checked, and I work with Kerio since 1999 - 24 years this year ....

[Updated on: Fri, 24 February 2023 12:45]

Report message to a moderator

Re: Kerio Control - Performance problem - Snort 3 [message #153866 is a reply to message #153838] Wed, 01 March 2023 03:39 Go to previous messageGo to next message
kres is currently offline  kres
Messages: 1
Registered: March 2023
Anyone tried that on a hardware server or VMware VM with good single-thread performance CPU?
I tested Control on a host with "up to" 500 Mbps uplink and it went 400/400. But I don't have 1Gpbs+ to test right now. And I have a client being interested but they have 10G uplink (I saw the port, do not know real connection width yet). What do? Years ago I loved Kerio, some old clients still use it...
Re: Kerio Control - Performance problem - Snort 3 [message #153881 is a reply to message #153866] Wed, 01 March 2023 14:01 Go to previous message
tverweij is currently offline  tverweij
Messages: 72
Registered: March 2010
Location: Curacao
I talked to support and as I understood, we can expect UEFI soon and Snort 3 not much later - so that should solve the performance issues as this (snort 3) makes the product scalable (scalable = Add extra CPU's for more performance). So we'll wait and see.

For the test with a good single-thread CPU: I do this on HyperV and reach 750 down and 350 up with a Xeon Silver 4210 (HT off and CStates off).
Snort 3 should be faster per CPU, but if I can scale the above, it needs 13 CPU's to get to 10 Gb down and 28 CPU's to get 10 Gb up. For a one GB line, 3 CPU's should be enough to get to the max.

So in my opinion it still needs hardware (AES-NI) acceleration to get the needed cores down as line speeds are continue to go up.

[Updated on: Wed, 01 March 2023 14:06]

Report message to a moderator

Next Topic: L2TP/IPSEc VPN in latest Android version with Kerio Control
Goto Forum:
  


Current Time: Fri Mar 24 17:02:32 CET 2023

Total time taken to generate the page: 0.01753 seconds