Howdy,

This update features three new major things: optional receive side scaling (RSS) support in the kernel, asynchronous DNS resolving for aliases and configuration support for advanced LAGG settings.

RSS is disabled by default but may be switched on by adding a tunable "net.inet.rss.enabled" with value "1" and rebooting the system. While RSS can improve performance for certain hardware it should be used with care at this point and is not generally recommended yet! The Suricata version bundled with the development release offers the upcoming API bindings to take advantage of the RSS-based multithreading. Also please note that PPPoE cannot take advantage of RSS.

On the side we are almost ready for our 22.1-BETA preview with rolling releases for the development release type which is something new to look forward to also.

Here are the full patch notes:


Stay safe,
Your OPNsense team