Hello all,

I have almost everything set up now. I spent all morning recompiling all my
network monitoring tools to use pf_ring and the pf_ring libpcap.
They all show up in /proc/net/pf_ring while running. yay!

Though, I can't use more than one application on a single NIC (each NIC is
PF_RING aware), I get a "pfring_set_channel_id() failed= -1" for any
additional sniffing application.
I'm running in transparent_mode 2 with the e1000 ring aware driver.
Using PF_RING v5.0.1
I need to run snort and ntop at all times.

Is this normal? I thought apps just read from the circular buffer, and there
wasn't a limit. Maybe there is for transparent_mode 2?
I looked through the User Guide, didn't find an answer.

Any help is appreciated.
Thanks
-- 
- Jon
-- 
------------------------------------------------------------------

VMB: 812-682-0231

Dubois County Linux User Group - http://www.dclinux.org
Southern Indiana Computer Klub - http://sickbits.networklabs.org
Bloomington FOOLS - http://www.bloomingtonfools.org/
BloomingLabs -  http://www.bloominglabs.org
ISSA-Kentuckiana  -  http://issa-kentuckiana.org

GPG Key ID: 810903CB
Key fingerprint = 0069 ED69 EABB DF84 5983  AD3C 6C20 BEFD 8109 03CB
_______________________________________________
Ntop-misc mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop-misc

Reply via email to