Snort mailing list archives

Re: BPF size on OpenBSD and multiple NICs


From: "skop d'skop" <skop () visto com>
Date: Sun, 10 Jun 2001 18:52:23 -0700

in my experience this packet drop is dealing with NIC. my box use Intel NIC.



-----Original Message-----
From:    Subba Rao subba9 () home com
Sent:    Sat, 9 Jun 2001 11:58:30 +0000
To:      snort-users () lists sourceforge net
Subject: [Snort-users] BPF size on OpenBSD and multiple NICs


What should be the limit of OpenBSD's BPF for running Snort effectively? I would
like to use one OpenBSD box with a 4-port NIC. Using TCPDUMP, I see quite a few
packets getting dropped (sometimes it is as much as 50%). Since Snort is the
other sniffer, this will be used for IDS. Does Snort drop packets as much as
TCPDUMP does?

From a performance point of view, how well do sensor's with 4-port NICs fair
over sensor with one port?

TIA.
-- 

Subba Rao
subba9 () home com
http://members.home.net/subba9/

GPG public key ID 27FC9217
Key fingerprint = 2B4C 498E 1860 5A2B 6570  5852 7527 882A 27FC 9217

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



___________________________________________________________________________
Visit http://www.visto.com/info, your free web-based communications center.
Visto.com. Life on the Dot.


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: