Dmitry Samersoff wrote:
> 

> I have stoped on perforamnce bpf itself.
> 
> Is there alternate driver or can changing of bpf queue in kernel help, and where
> I can read about it?

If my memory serves me correctly, Marcus Ranum wrote a white paper on
IDS systems in the early days of NFR, in which he said that the existing
configuration of BPF was inadequate for capturing all packets on a fast
link, and suggested a patch to improve the situation. THe patch involved
bumping up a buffer from about 16kb to 256kb. Unfortunately I no longer
have the details handy, but if you did a search for BPF/IDS/NFR/Ranum
you might find something.


-- 
Dr Graham Wheeler                        E-mail: [EMAIL PROTECTED]
Director, Research and Development       WWW:    http://www.cequrux.com
CEQURUX Technologies                     Phone:  +27(21)423-6065
Firewalls/VPN Specialists                Fax:    +27(21)424-3656


To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-hackers" in the body of the message

Reply via email to