Hi,
what are your recommendation for transparent_mode when I have
applications both using pf_ring (bro, snort, nprobe) and a single one
that does not (netsniff-ng)?
Should I run it with mode 1? My understanding is, the overhead should be
bigger here, because we have like two paths for data copying running at
the same time. Or does the shortcut, made by mode 1 for pf_ring
applications work so well that it's still better than just using NAPI
for everything?
I guess, there's a reason you implemented "something in the middle" -
i.e. mode 1, just curious.
Unfortunately, I cannot (yet) run a full DNA, but working on it ;) Will
have to hack the netsniff-ng to add a pf_ring support.
_______________________________________________
Ntop-misc mailing list
[email protected]
http://listgateway.unipi.it/mailman/listinfo/ntop-misc