Snort mailing list archives

RE: Advice on quad ethernet card


From: "Darden, Patrick S." <darden () armc org>
Date: Fri, 19 Nov 2004 15:36:58 -0500


I don't think this is a good idea.  You will see a lot of drops if you have
any amount of traffic at all.  If you simply must have this on one box, then
get two dual-ethernet cards, and make sure they are each on a different
internal bus, and put the two lightest trafficced networks on the same card.
That might help.

With a potential of about ~210Mbps (3*70), you shouldn't need a super-fast
disk subsystem at ~25MBps (210Mbps/8) written, but you should make it SCSI
in order to reduce CPU utilization.  The 3 network connections will take up
some cpu, snort itself will take up a bit, and if you use a large ruleset
you could be swamped (IOs for each of the cards and the disks).

I take it the 4'th nic is going to be used to send data to your remote mysql
server....  This could be the straw that breaks the camel's back.

It will be interesting to see how well this works!

--Patrick Darden
--snort, ids, cisco, unix
--linux, firewalls, security


-----Original Message-----
From: Patrick Marquetecken [mailto:patrick.marquetecken () pandora be]
Sent: Friday, November 19, 2004 4:16 PM
To: Snort
Subject: [Snort-users] Advice on quad ethernet card


Hi,

At my work they are thinking of replacing 3 snort machines by one with a
quad Ethernet card, witch will sniff 3 different lan's.
The network is only 100Mbit, will there not a lot of dropped packages this
way, and they must all send there data with barnyard to a remote mysql
server.
Is it also possible to see in the Database from witch sensor the data is
from? 

TIA
Patrick

-- 
"Please, Spock, do me a favor ... 'n' don't say it's `fascinating'..."
"No... but it is... interesting..." -- Spock

Fingerprint = 2792 057F C445 9486 F932 3AEA D3A3 1B0C 1059 273B
ICQ# 316932703 
Registered Linux User #44550
http://counter.li.org



-------------------------------------------------------
This SF.Net email is sponsored by: InterSystems CACHE
FREE OODBMS DOWNLOAD - A multidimensional database that combines
robust object and relational technologies, making it a perfect match
for Java, C++,COM, XML, ODBC and JDBC. www.intersystems.com/match8
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: