Snort mailing list archives

BPF size on OpenBSD and multiple NICs


From: Subba Rao <subba9 () home com>
Date: Sat, 9 Jun 2001 11:58:30 +0000

What should be the limit of OpenBSD's BPF for running Snort effectively? I would
like to use one OpenBSD box with a 4-port NIC. Using TCPDUMP, I see quite a few
packets getting dropped (sometimes it is as much as 50%). Since Snort is the
other sniffer, this will be used for IDS. Does Snort drop packets as much as
TCPDUMP does?

From a performance point of view, how well do sensor's with 4-port NICs fair
over sensor with one port?

TIA.
-- 

Subba Rao
subba9 () home com
http://members.home.net/subba9/

GPG public key ID 27FC9217
Key fingerprint = 2B4C 498E 1860 5A2B 6570  5852 7527 882A 27FC 9217

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: