[Snort-users] Ethernet options

Jaime Nebrera jnebrera at ...11827...
Thu Mar 8 03:17:42 EST 2012


   Hi Heine,

> Try taking a look at this blog post from SecurityOnion
> http://securityonion.blogspot.com/2011/10/when-is-full-packet-capture-not-full.html

   Wow, thanks for the info. Its clear that GRO and such are not a good 
idea as they "build" super packets that might be problematic.

   Still, how about RX/TX checksum offloading? I think this ones should 
be ok, do they?




More information about the Snort-users mailing list