<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>dataplane :: Tag :: BIFIT Mitigator</title>
    <link>https://docs.mitigator.ru/v26.08/en/tags/dataplane/</link>
    <description></description>
    <generator>Hugo</generator>
    <language>en</language>
    <atom:link href="https://docs.mitigator.ru/v26.08/en/tags/dataplane/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>MITIGATOR Installation</title>
      <link>https://docs.mitigator.ru/v26.08/en/install/manual/mitigator/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.mitigator.ru/v26.08/en/install/manual/mitigator/</guid>
      <description>All files are supposed to be placed in the /srv/mitigator working directory:&#xA;mkdir -p /srv/mitigator &amp;&amp; \ cd /srv/mitigator 1. Docker Compose Place base Docker Compose configuration in the working directory:&#xA;wget https://docs.mitigator.ru/v26.08/dist/docker-compose.yml Download base variable file and save it as .env:&#xA;wget https://docs.mitigator.ru/v26.08/dist/env -O /srv/mitigator/.env In the .env file, specify:&#xA;System version (VERSION). The microarchitecture of the processor from the list specified in the (ARCH) example file. The maximum number of IPv4 protection policies (DATA_PLANE_NR_POLICIES). The maximum number of IPv6 protection policies (DATA_PLANE_NR_POLICIES_IPV6). Instance name in the cluster (MITIGATOR_OWN_NAME, required). IP address for container-to-host access (MITIGATOR_HOST_ADDRESS, required). IP address or domain name for API and UI clients (MITIGATOR_PUBLIC_ADDRESS, required). Master secret used to encrypt sensitive settings (MITIGATOR_MASTER_SECRET, required). When running in a cluster, master secret must be the same on all MITIGATOR instances. Proxy for the license server (ls.mitigator.ru), mail notifications and the Vestochka service. Time zone (TZ). Token for interaction between the backend and the watchhog (TOKEN). The .env file is set to TOKEN by default. It is required to change it. When running in a cluster, TOKEN must be the same on all MITIGATOR instances. These settings are described in detail inside the example file.</description>
    </item>
    <item>
      <title>Core Isolation for Performance Optimization</title>
      <link>https://docs.mitigator.ru/v26.08/en/kb/isolcpus/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.mitigator.ru/v26.08/en/kb/isolcpus/</guid>
      <description>By default, the CPU cores that work with network ports are also used by other subsystems. This can degrade performance and cause Input Errors pps/bps spikes on Port extX/intX graphs. You can take some of the load off these cores by preventing non-critical subsystems from running on them.&#xA;To do so:&#xA;Specify isolation of the packet processor cores in the core options through the isolcpus=... and rcu_nocbs=... parameters. It is also recommended to add mitigations=off to disable core security patches.</description>
    </item>
    <item>
      <title>Troubleshooting</title>
      <link>https://docs.mitigator.ru/v26.08/en/install/troubleshooting/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.mitigator.ru/v26.08/en/install/troubleshooting/</guid>
      <description>Drivers not loading (modprobe) Symptoms:&#xA;When loading a module:&#xA;modprobe: FATAL: Module igb_uio not found in directory /lib/modules/4.9.0-6-amd64 When installing a package:&#xA;Module build for kernel 4.9.0-6-amd64 was skipped since the kernel headers for this kernel does not seem to be installed. You need to install the linux-headers-amd64 (Debian) package and make sure that the kernel version corresponding to the version of this package is loaded, then run:</description>
    </item>
    <item>
      <title>Packet Processor Settings</title>
      <link>https://docs.mitigator.ru/v26.08/en/kb/dataplane.conf/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://docs.mitigator.ru/v26.08/en/kb/dataplane.conf/</guid>
      <description>The packet processor is configured through the dataplane.conf file.&#xA;Put the file into the MITIGATOR working directory and set the required parameters. Other parameters will have the default values.&#xA;Comments are specified with #, // or /* */.&#xA;Available parameters (with default values):&#xA;# Control socket bind address. control_address: 0.0.0.0 # Control socket TCP port. # [1, 65535] control_port: 8888 # Debug control socket TCP port. # [1, 65535] debug_port: 8889 # gRPC control socket TCP port. # [1, 65535] grpc_port: 8890 # Sync/web-challenger control socket UDP port. # [1, 65535] sync_udp_port: 8891 # Number of control socket processing threads. # [1, 1000] control_threads: 20 # Control socket request timeout (seconds). # [1, 10000] control_request_timeout: 15 # Control socket request/response content timeout (seconds). # [1, 10000] control_content_timeout: 300 # Enable control socket event log. control_log: false # Control socket event log message length limit. # [0, 100000] control_log_limit: 100 # Number of sync task threads. # [1, 1000] sync_threads: 10 # Enable sync task log. sync_log: false # Enable additional cores for sync/web-challenger control socket. use_extra_service_cores: false # MAC address of emitted challenge packets. challenge_mac: &lt;not set&gt; # VLAN ID of emitted challenge packets. # [1, 4095] challenge_vlan_id: &lt;not set&gt; # LACP system ID. # Set to local MAC address if not specified. lacp_system_id: &lt;auto-detect&gt; # LACP port operational key. # [0, 65535] lacp_oper_key: 1000 # MAC resolver request retransmit delay (seconds). # [1, 10000] mac_retransmit_time: 5 # MAC resolver entry validity period (seconds). # [1, 10000] mac_reachable_time: 30 # MAC resolver stale entry cleanup timeout (seconds). # [1, 10000] mac_stale_time: 60 # Maximum allowed number of IPv4 policies. # [1, 60000] max_policies: 100 # Maximum allowed number of IPv6 policies. # [1, 60000] max_policies6: 100 # Maximum allowed SIMD instruction bitwidth. # [0, 512] max_simd_bitwidth: &lt;auto-detect&gt; # Size of network packet memory pool (per NUMA node). # [0, 2^31] packet_mempool_size: &lt;auto-detect&gt; # Enable deferred start of packet processing. # Starts ports only after full application initialization. # Prevents network traffic loops. deferred_start: false # Enable special processing mode of dual-port NICs (for `port_direct_mode: true`). # Process each port on a separate set of cores. # Improves performance for 100G or larger ports when both ports are used. dual_port_nic: false # RX checksum offloading policy: # `false` - do not request the offloading, force software checksum verification. # `true` - enable the offloading for all ports if supported. # Enables offloading only for physical ports if not specified. port_checksum_offload: &lt;auto-detect&gt; # Processing mode of network port I/O queues: # `false` - process port I/O queues on dedicated cores, # recommended for low speeds. # `true` - process port I/O queues on worker cores, # recommended for 100G or higher speeds. port_direct_mode: &lt;auto-detect&gt; # Network port link speed (Mb/s). # Disables speed autonegotiation if enabled. # [100|1000|10000|...] or [100M|1G|10G|...] port_link_speed: &lt;auto-negotiate&gt; # Enable link state propagation of port pairs. port_lsp: false # Network port MTU. # [0, 65535] port_mtu: 1500 # Size of packet ring buffers between network port I/O queue processing cores # and worker cores (for `port_direct_mode: false`). # [0, 2^20] port_ring_size: 8192 # Number of network port RX descriptors. # [0, 65535] port_rx_desc: &lt;auto-detect&gt; # Number of network port TX descriptors. # [0, 65535] port_tx_desc: &lt;auto-detect&gt; # Maximum number of retry attempts of network port packet TX. # [0, 2^31] port_tx_retries: 128 # Network port I/O queue processing cores. # Range list [0, 255] port_cores: &lt;auto-detect&gt; # Number of network port I/O queue processing cores (per NUMA node). # [0, 256] port_cores_nr: &lt;auto-detect&gt; # NUMA nodes of network port I/O queue processing cores. # Range list [0, 7] or `all`: # `all` - use all nodes. port_nodes: &lt;auto-detect&gt; # Worker cores. # Range list [0, 255] worker_cores: &lt;auto-detect&gt; # Number of worker cores (per NUMA node). # [0, 256] worker_cores_nr: &lt;auto-detect&gt; # Worker core NUMA nodes. # Range list [0, 7] or `all`: # `all` - use all nodes. worker_nodes: &lt;auto-detect&gt; # Network port list. # Defines network ports used by packet processor. # Configures port pairs, port zones and their order. # Auto-configured for all detected ports if not specified. # If specified, all used ports must be listed. # # Format: # &lt;port_zone&gt; [ext|int] &lt;pair_index&gt; [0, 255] : &lt;port_id&gt; # port_id: # &lt;pci_address&gt; or &lt;port_number&gt; [0, 255] or &lt;port_name&gt; (string). # # Example: ext0: 01:00.0 int0: 01:00.1 ext1: 04:00.0 int1: 04:00.1 Related Content Core Isolation for Performance Optimization Access to the Grafana Interface Configuration Change Configuring Tiered Protection with MITIGATOR Graphite on a Separate Server Incident Chart Update Period MITIGATOR Installation Pgfailover Documentation Setting the Storage Time for Metrics in Graphite System Setup for Mellanox (NVIDIA) Adapters</description>
    </item>
  </channel>
</rss>