Snort mailing list archives
RE: Advice on quad ethernet card
From: "Darden, Patrick S." <darden () armc org>
Date: Fri, 19 Nov 2004 15:36:58 -0500
I don't think this is a good idea. You will see a lot of drops if you have any amount of traffic at all. If you simply must have this on one box, then get two dual-ethernet cards, and make sure they are each on a different internal bus, and put the two lightest trafficced networks on the same card. That might help. With a potential of about ~210Mbps (3*70), you shouldn't need a super-fast disk subsystem at ~25MBps (210Mbps/8) written, but you should make it SCSI in order to reduce CPU utilization. The 3 network connections will take up some cpu, snort itself will take up a bit, and if you use a large ruleset you could be swamped (IOs for each of the cards and the disks). I take it the 4'th nic is going to be used to send data to your remote mysql server.... This could be the straw that breaks the camel's back. It will be interesting to see how well this works! --Patrick Darden --snort, ids, cisco, unix --linux, firewalls, security -----Original Message----- From: Patrick Marquetecken [mailto:patrick.marquetecken () pandora be] Sent: Friday, November 19, 2004 4:16 PM To: Snort Subject: [Snort-users] Advice on quad ethernet card Hi, At my work they are thinking of replacing 3 snort machines by one with a quad Ethernet card, witch will sniff 3 different lan's. The network is only 100Mbit, will there not a lot of dropped packages this way, and they must all send there data with barnyard to a remote mysql server. Is it also possible to see in the Database from witch sensor the data is from? TIA Patrick -- "Please, Spock, do me a favor ... 'n' don't say it's `fascinating'..." "No... but it is... interesting..." -- Spock Fingerprint = 2792 057F C445 9486 F932 3AEA D3A3 1B0C 1059 273B ICQ# 316932703 Registered Linux User #44550 http://counter.li.org ------------------------------------------------------- This SF.Net email is sponsored by: InterSystems CACHE FREE OODBMS DOWNLOAD - A multidimensional database that combines robust object and relational technologies, making it a perfect match for Java, C++,COM, XML, ODBC and JDBC. www.intersystems.com/match8 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Advice on quad ethernet card Patrick Marquetecken (Nov 19)
- Re: Advice on quad ethernet card Glenn Forbes Fleming Larratt (Nov 29)
- Re: Advice on quad ethernet card sekure (Nov 29)
- <Possible follow-ups>
- RE: Advice on quad ethernet card Darden, Patrick S. (Nov 19)
- RE: Advice on quad ethernet card Richard Bejtlich (Nov 19)
- Re: Advice on quad ethernet card Glenn Forbes Fleming Larratt (Nov 29)