On Sep 28, 2011, at 11:21 PM, Jon Schipp wrote:

> Hello all,
> 
> I have almost everything set up now. I spent all morning recompiling all my 
> network monitoring tools to use pf_ring and the pf_ring libpcap.
> They all show up in /proc/net/pf_ring while running. yay!
> 
> Though, I can't use more than one application on a single NIC (each NIC is 
> PF_RING aware), I get a "pfring_set_channel_id() failed= -1" for any 
> additional sniffing application.
> I'm running in transparent_mode 2 with the e1000 ring aware driver. Using 
> PF_RING v5.0.1
> I need to run snort and ntop at all times. 

Jon
you should be able to run both applications at the same time, unless you are 
using quick_mode.
how did you load the kernel module?

Alfredo

> 
> Is this normal? I thought apps just read from the circular buffer, and there 
> wasn't a limit. Maybe there is for transparent_mode 2? 
> I looked through the User Guide, didn't find an answer.
> 
> Any help is appreciated. 
> Thanks
> -- 
> - Jon
> -- 
> ------------------------------------------------------------------
> 
> VMB: 812-682-0231 
> 
> Dubois County Linux User Group - http://www.dclinux.org
> Southern Indiana Computer Klub - http://sickbits.networklabs.org
> Bloomington FOOLS - http://www.bloomingtonfools.org/
> BloomingLabs -  http://www.bloominglabs.org
> ISSA-Kentuckiana  -  http://issa-kentuckiana.org
> 
> GPG Key ID: 810903CB
> Key fingerprint = 0069 ED69 EABB DF84 5983  AD3C 6C20 BEFD 8109 03CB
> 
> _______________________________________________
> Ntop-misc mailing list
> [email protected]
> http://listgateway.unipi.it/mailman/listinfo/ntop-misc

_______________________________________________
Ntop-misc mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop-misc

Reply via email to