Hello all, I have almost everything set up now. I spent all morning recompiling all my network monitoring tools to use pf_ring and the pf_ring libpcap. They all show up in /proc/net/pf_ring while running. yay!
Though, I can't use more than one application on a single NIC (each NIC is PF_RING aware), I get a "pfring_set_channel_id() failed= -1" for any additional sniffing application. I'm running in transparent_mode 2 with the e1000 ring aware driver. Using PF_RING v5.0.1 I need to run snort and ntop at all times. Is this normal? I thought apps just read from the circular buffer, and there wasn't a limit. Maybe there is for transparent_mode 2? I looked through the User Guide, didn't find an answer. Any help is appreciated. Thanks -- - Jon -- ------------------------------------------------------------------ VMB: 812-682-0231 Dubois County Linux User Group - http://www.dclinux.org Southern Indiana Computer Klub - http://sickbits.networklabs.org Bloomington FOOLS - http://www.bloomingtonfools.org/ BloomingLabs - http://www.bloominglabs.org ISSA-Kentuckiana - http://issa-kentuckiana.org GPG Key ID: 810903CB Key fingerprint = 0069 ED69 EABB DF84 5983 AD3C 6C20 BEFD 8109 03CB
_______________________________________________ Ntop-misc mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop-misc
