I have an inline IPS installation of suricata v4.1.10 on Centos 7 with NFQUEUE on a virtual Cloud environment.
The installation work fine but my network bandwith is divided by around 3 when activating inline IPS.
Is that normal ? I don’t expect to have full bandwith capacity with IPS but this is a huge difference (from 300 MBps to less than 100 MBps) ? I tried the tuning instructions provided by documentation but it did not helped.
Have you an idea of specific tuning to increase bandwith ?
Thanks for your help,