Hello, We're exploring using PF-RING ZC for our packet sniffers, but are looking to get clarity on an issue before purchasing licenses.
The sniffers are standard servers running Linux, each with (16) 10G NIC ports connected to SPAN ports on switches. Users log into the system and run TCPDUMP to troubleshoot day-to-day connectivity issues in the environment. As traffic levels have increased we're seeing more and more drops on the NICs, so the thought was to implement ZC to make things better. But it looks like ZC may limit us to one capture per NIC at any given time. Is this correct? I see text on the product page about not being able to do standard networking activities on a given NIC when ZC is actively running, but how about multiple ZC-enabled TCPDUMPs at once? It doesn't seem to work for us (getting a "No such device" error), but maybe it's something we're doing wrong. Would appreciate any guidance. -Terry
_______________________________________________ Ntop-misc mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop-misc
