Snort mailing list archives
BPF size on OpenBSD and multiple NICs
From: Subba Rao <subba9 () home com>
Date: Sat, 9 Jun 2001 11:58:30 +0000
What should be the limit of OpenBSD's BPF for running Snort effectively? I would like to use one OpenBSD box with a 4-port NIC. Using TCPDUMP, I see quite a few packets getting dropped (sometimes it is as much as 50%). Since Snort is the other sniffer, this will be used for IDS. Does Snort drop packets as much as TCPDUMP does?
From a performance point of view, how well do sensor's with 4-port NICs fair
over sensor with one port? TIA. -- Subba Rao subba9 () home com http://members.home.net/subba9/ GPG public key ID 27FC9217 Key fingerprint = 2B4C 498E 1860 5A2B 6570 5852 7527 882A 27FC 9217 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- BPF size on OpenBSD and multiple NICs Subba Rao (Jun 09)
- Re: BPF size on OpenBSD and multiple NICs Phil Wood (Jun 09)
- <Possible follow-ups>
- Re: BPF size on OpenBSD and multiple NICs skop d'skop (Jun 10)