snort-users October 2010 archive
Main Archive Page > Month Archives  > snort-users archives
snort-users: Re: [Snort-users] Snort 2.9, RHEL 5 and afpacket DA

Re: [Snort-users] Snort 2.9, RHEL 5 and afpacket DAQ

From: Ralf Spenneberg <ralf_at_nospam>
Date: Tue Oct 19 2010 - 05:39:34 GMT
To: Russ Combs <rcombs@sourcefire.com>

Hi Russ,

Am Montag, den 18.10.2010, 15:36 -0400 schrieb Russ Combs:
> Check the DAQ distro README for how to use this option:
> --daq-var buffer_size_mb=<#MB>
> You pass that to Snort which gives it to afpacket.

Thanks a lot for the suggestion, but Looking at the source it should use
a default of 128M if nothing is specified.

Anyway. I played around with the option and apparently I can set it to
49M but not more on this system. Therefore the default did not work!
System:
RHEL5, 4GB, 64bit Kernel: 2.6.18-194.el5

Any clue what might be the restricting factor? Oh, by the way using
PCAP-FRAMES I can use a 2GB ring buffer, so it must be some special
restriction to the afpacket ringbuffer.

Any ideas? Anybody else using the feature on RHEL/CentOS?

Ralf

------------------------------------------------------------------------------
Download new Adobe(R) Flash(R) Builder(TM) 4
The new Adobe(R) Flex(R) 4 and Flash(R) Builder(TM) 4 (formerly
Flex(R) Builder(TM)) enable the development of rich applications that run
across multiple browsers and platforms. Download your free trials today!
http://p.sf.net/sfu/adobe-dev2dev
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users