On 2020-01-15 1:13 PM, Владислав Дубов wrote:

> Thank you. is our pfSense router, which hosts Suricata and
> connects our LAN to the outside WAN. 
  Ah. That's helpful.
  I also wanted the IP address for whatsapp.com for your locale.

  Looking at the log, at 10:56:07 a lot of DNS requests are listed, followed by
some email, then a large amount of traffic between and It continues throughout the day.

> When the 'messy' things start, I cannot even open the Whatsapp home page in my
> browser.
  How much memory does the router have?
  How much free RAM is available when Suricata is running? If the router is
swapping to disk, that slows processing to teletype speeds.
  What is the CPU usage when Suricata is running? Suricata is quite demanding of
CPU resources.

  Please try disabling the SURICATA rules. In disable.conf add:
# Disable all SURICATA rules

James Moe
moe dot james at sohnen-moe dot com

