Snort mailing list archives

Re: snort and bonding


From: Michael Boman <michael.boman () securecirt com>
Date: Sun, 9 Mar 2003 14:03:29 +0800

On Fri, Mar 07, 2003 at 06:38:23PM +0100, Patrice Boulanger wrote:
Hello everyone,

Does anyone have already used snort with network interface bonding ? Is it
easy to use such an interface to be able to listen more traffic (for example
by using 4 interfaces to listen up to 400Mbits of traffic) ?

Thanks

Bonding is useful when you are using taps. To use 4 NIC's to sniff 400
Mbps is doable, but more concideration has to be given to load-balancing,
BPF filters etc... What exactly are you trying to do?

/Mike

-- 
Michael Boman
Security Architect, SecureCiRT Pte Ltd
http://www.securecirt.com

Attachment: _bin
Description:


Current thread: