Snort mailing list archives

Re: Snort 2.9, RHEL 5 and afpacket DAQ


From: Ralf Spenneberg <ralf () spenneberg de>
Date: Tue, 19 Oct 2010 07:39:34 +0200

Hi Russ,

Am Montag, den 18.10.2010, 15:36 -0400 schrieb Russ Combs:
Check the DAQ distro README for how to use this option:
--daq-var buffer_size_mb=<#MB>
You pass that to Snort which gives it to afpacket.

Thanks a lot for the suggestion, but Looking at the source it should use
a default of 128M if nothing is specified.

Anyway. I played around with the option and apparently I can set it to
49M but not more on this system. Therefore the default did not work!
System:
RHEL5, 4GB, 64bit Kernel: 2.6.18-194.el5

Any clue what might be the restricting factor? Oh, by the way using
PCAP-FRAMES I can use a 2GB ring buffer, so it must be some special
restriction to the afpacket ringbuffer.

Any ideas? Anybody else using the feature on RHEL/CentOS?

Ralf





------------------------------------------------------------------------------
Download new Adobe(R) Flash(R) Builder(TM) 4
The new Adobe(R) Flex(R) 4 and Flash(R) Builder(TM) 4 (formerly 
Flex(R) Builder(TM)) enable the development of rich applications that run
across multiple browsers and platforms. Download your free trials today!
http://p.sf.net/sfu/adobe-dev2dev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: