10Gbps Forward Nodes hardware #12222
Replies: 3 comments 8 replies
-
You're anticipating sustained traffic of 10Gb/sec? |
Beta Was this translation helpful? Give feedback.
-
Just curious, but who or what's the perspective on this God-like telco-level view into a chunk 'o fiber? Sounds like really interesting state-sponsored or Big Tech-level stuff... |
Beta Was this translation helpful? Give feedback.
-
Forgot to say I will use 2 (or even 3 if not enough cores to handle zeek and suricata) servers as forward nodes. But yeah, guess NVMe is still the safest bet |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
I'd like to build a Proof of concept with Security Onion, starting with 10Gbps, but due to budgetary restrictions I'm forced to save money wherever possible.
One of the goals is to store full pcaps with a retention of a few days. At 10Gbps, one day will already exceed 80TB.
My question is, can I use SAS HDD instead of SSD for the forward nodes?
In other words, will HDDs bottleneck and cause packet drops? And if so, would adding Smart NICs like Napatech or Accolade overcome this problem?
Especially when the analysts will query for Pcaps during Hunts.
I'd like to use RAID 6 over RAID 10 as the latter would cut the total storage in half.
Of course, if the only solution in order to use HDD is using RAID10 I will use this configuration.
The forward nodes will have to process Zeek, Suricata and Strelka as well.
I will probably use older gen hardware and was looking at E5-2699AV4 and/or AMD EPYC 7763.
Are there any known issues running SO 2.4 with these CPU's and related motherboards?
All inputs are much appreciated :-)
Thanks!
Beta Was this translation helpful? Give feedback.
All reactions