[Snort-users] Snort-users Digest, Vol 75, Issue 79
ste at ...15794...
Fri Aug 31 07:00:49 EDT 2012
-----BEGIN PGP SIGNED MESSAGE-----
Il 30/08/2012 18:02, snort-users-request at lists.sourceforge.net ha >
> Date: Thu, 30 Aug 2012 16:43:52 +0100 From: Peter Bates
> <peter.bates at ...15381...> Subject: Re: [Snort-users] Large receive
> offload, good or bad? To: <snort-users at lists.sourceforge.net>
> Message-ID: <503F8A38.503 at ...15381...> Content-Type: text/plain;
> Hello all
> Interesting topic, as I've been pondering the same thing this
> On 30/08/2012 15:59, Joel Esler wrote:
>> If I was deploying an I[DP]S I would investigate using a
>> operating system and network card that supports zero copy bpf
>> sockets. This will save you much more CPU time than using LRO and
>> have much more predictable results.
> Can the VRT member who is not on the list expand a bit more on
> Are we talking *BSD, Linux AF_PACKET with fanout, PF_RING, ?
interesting topic indeed, netmap , PFQ , anyone?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.19 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
-----END PGP SIGNATURE-----
More information about the Snort-users