[Snort-users] snort on obsd performance

Erek Adams erek at ...577...
Fri Sep 7 20:48:02 EDT 2001


On Fri, 7 Sep 2001, skop d'skop wrote:

> yet my server still can't handle large traffic (2+2)  even with -A fast .
> recently it stop the service after 30-40 minutes of running (snort -d -A
> fast -c snort.conf -l /var/log/snort ) surprising it works well as on same
> set up for firewall using ipf/ipnat.
>
> anyone has tips on improving the performance / tuning of openbsd to handle
> large traffic ?

It might be the big meal I just had ;-) but I'm a little fuzzy on the whole
'large traffic' thing.  Can you define the type of traffic you're trying to
snort?  TCP?  UDP?  ICMP?  Packet size?  Also, what version of snort?  What
does your snort.conf look like?  Plugins?  Preprocessors?

Must make it to couch....  Nappy time coming on ....   Must resist....
zzzzzz...  *snore*

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net






More information about the Snort-users mailing list