Russell Fulton
2013-07-28 00:15:46 UTC
Hi
The next decision I need to make is whether to use pf_ring or af_packet. From what I can garner with google if you are just running suri on the sensor af_packet is flavour of the month. However I have found references that suggest that if one wants to run other packages like argus and bro along side then pf_ring is preferred.
Can anyone point me to a document that spells out the pros and cons of the two?
Thanks, Russell
_______________________________________________
Suricata IDS Users mailing list: oisf-users-***@public.gmane.org
Site: http://suricata-ids.org | Support: http://suricata-ids.org/support/
List: https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users
OISF: http://www.openinfosecfoundation.org/
The next decision I need to make is whether to use pf_ring or af_packet. From what I can garner with google if you are just running suri on the sensor af_packet is flavour of the month. However I have found references that suggest that if one wants to run other packages like argus and bro along side then pf_ring is preferred.
Can anyone point me to a document that spells out the pros and cons of the two?
Thanks, Russell
_______________________________________________
Suricata IDS Users mailing list: oisf-users-***@public.gmane.org
Site: http://suricata-ids.org | Support: http://suricata-ids.org/support/
List: https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users
OISF: http://www.openinfosecfoundation.org/