OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: RE: [Snort-users] snort dying quietly
From: Dr SuSE (drsusedrsuse.org)
Date: Mon Nov 27 2000 - 23:52:46 CST


Since were on the subject of network cards, has anyone done any testing to
find out which cards offer the best performance with Snort?

Dr SuSE

"Microsoft ist nicht installiert"

On Tue, 28 Nov 2000, Austad, Jay wrote:

> Snort doesn't die on my box, but I get console messages that say "eth1: card
> reports no resources". It's an Intel EEpro100 on a PIII 700. It is
> sniffing traffic on a portion of our network that serves out about 3 or 4
> million page views a day. Total bandwidth is about 32Mbit/sec during the
> day. I'll probably be moving snort to a different box sometime this week
> which has 3com cards in it.
>
> Jay
>
> > -----Original Message-----
> > From: Fyodor [mailto:fygravetigerteam.net]
> > Sent: Tuesday, November 28, 2000 7:16 AM
> > To: Juergen Schmidt
> > Cc: snort-userslists.sourceforge.net
> > Subject: Re: [Snort-users] snort dying quietly
> >
> >
> > > traffic site (2 million page views per day) I started with snort
> > > ignoring HTTP traffic (i.e. I appended "not \( port 80 \)"
> > at the end of
> > > the snort invocation). As ruleset I use the vision.rules.
> > >
> > > I get regular messages " kernel: eth0: card reports no
> > resources." and
> >
> > Snort will exit with error message if your network interface goes down
> > for the moment. I think that's what you may be having here. As for
> > the reason why you have this message, I can only guess that it might
> > be promisc. mode which overloads your card since it has to
> > process more
> > data than it does normally. I'd try to get different card installed
> > and see if it improves the situation :)
> >
> >
> > --
> > http://www.notlsd.net
> > PGP fingerprint = 56DD 1511 DDDA 56D7 99C7 B288 5CE5 A713 0969 A4D1
> > _______________________________________________
> > Snort-users mailing list
> > Snort-userslists.sourceforge.net
> > http://lists.sourceforge.net/mailman/listinfo/snort-users
> >
> _______________________________________________
> Snort-users mailing list
> Snort-userslists.sourceforge.net
> http://lists.sourceforge.net/mailman/listinfo/snort-users
>

_______________________________________________
Snort-users mailing list
Snort-userslists.sourceforge.net
http://lists.sourceforge.net/mailman/listinfo/snort-users