tcpdump mailing list archives

A question about performance (sniffing from NIC or read pcap dump)


From: Michael Boman <michael.boman () securecirt com>
Date: 11 Jul 2003 10:29:37 +0800

Hi,

I wonder how performance is effected in the following scenarios:


Scenario 1:
 1) tcpdump sniffs traffic and write it to a file
 2) Other pcap based software is reading the file and do their stuff

Scenario 2:
 1) Each application connects to the NIC them self and all do their own
sniffing, and of course do what they need to do with the packet later
on.


Basically I'd like your advice if Scenario 1 or 2 is the most efficient
way to do stuff.


Best regards
 Michael Boman

-- 
Michael Boman
Security Architect, SecureCiRT Pte Ltd
http://www.securecirt.com

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: