Dmitry Samersoff wrote:
>
> I have stoped on perforamnce bpf itself.
>
> Is there alternate driver or can changing of bpf queue in kernel help, and where
> I can read about it?
If my memory serves me correctly, Marcus Ranum wrote a white paper on
IDS systems in the early days of NFR, in which he said that the existing
configuration of BPF was inadequate for capturing all packets on a fast
link, and suggested a patch to improve the situation. THe patch involved
bumping up a buffer from about 16kb to 256kb. Unfortunately I no longer
have the details handy, but if you did a search for BPF/IDS/NFR/Ranum
you might find something.
--
Dr Graham Wheeler E-mail: [EMAIL PROTECTED]
Director, Research and Development WWW: http://www.cequrux.com
CEQURUX Technologies Phone: +27(21)423-6065
Firewalls/VPN Specialists Fax: +27(21)424-3656
To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-hackers" in the body of the message