Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: NTop: Misc

[PF_RING] can't use multiple applications on PF_RING device

 

 

NTop misc RSS feed   Index | Next | Previous | View Threaded


jonschipp at gmail

Sep 28, 2011, 2:21 PM

Post #1 of 3 (367 views)
Permalink
[PF_RING] can't use multiple applications on PF_RING device

Hello all,

I have almost everything set up now. I spent all morning recompiling all my
network monitoring tools to use pf_ring and the pf_ring libpcap.
They all show up in /proc/net/pf_ring while running. yay!

Though, I can't use more than one application on a single NIC (each NIC is
PF_RING aware), I get a "pfring_set_channel_id() failed= -1" for any
additional sniffing application.
I'm running in transparent_mode 2 with the e1000 ring aware driver.
Using PF_RING v5.0.1
I need to run snort and ntop at all times.

Is this normal? I thought apps just read from the circular buffer, and there
wasn't a limit. Maybe there is for transparent_mode 2?
I looked through the User Guide, didn't find an answer.

Any help is appreciated.
Thanks
--
- Jon
--
------------------------------------------------------------------

VMB: 812-682-0231

Dubois County Linux User Group - http://www.dclinux.org
Southern Indiana Computer Klub - http://sickbits.networklabs.org
Bloomington FOOLS - http://www.bloomingtonfools.org/
BloomingLabs - http://www.bloominglabs.org
ISSA-Kentuckiana - http://issa-kentuckiana.org

GPG Key ID: 810903CB
Key fingerprint = 0069 ED69 EABB DF84 5983 AD3C 6C20 BEFD 8109 03CB


cardigliano at ntop

Sep 28, 2011, 2:36 PM

Post #2 of 3 (345 views)
Permalink
Re: [PF_RING] can't use multiple applications on PF_RING device [In reply to]

On Sep 28, 2011, at 11:21 PM, Jon Schipp wrote:

> Hello all,
>
> I have almost everything set up now. I spent all morning recompiling all my network monitoring tools to use pf_ring and the pf_ring libpcap.
> They all show up in /proc/net/pf_ring while running. yay!
>
> Though, I can't use more than one application on a single NIC (each NIC is PF_RING aware), I get a "pfring_set_channel_id() failed= -1" for any additional sniffing application.
> I'm running in transparent_mode 2 with the e1000 ring aware driver. Using PF_RING v5.0.1
> I need to run snort and ntop at all times.

Jon
you should be able to run both applications at the same time, unless you are using quick_mode.
how did you load the kernel module?

Alfredo

>
> Is this normal? I thought apps just read from the circular buffer, and there wasn't a limit. Maybe there is for transparent_mode 2?
> I looked through the User Guide, didn't find an answer.
>
> Any help is appreciated.
> Thanks
> --
> - Jon
> --
> ------------------------------------------------------------------
>
> VMB: 812-682-0231
>
> Dubois County Linux User Group - http://www.dclinux.org
> Southern Indiana Computer Klub - http://sickbits.networklabs.org
> Bloomington FOOLS - http://www.bloomingtonfools.org/
> BloomingLabs - http://www.bloominglabs.org
> ISSA-Kentuckiana - http://issa-kentuckiana.org
>
> GPG Key ID: 810903CB
> Key fingerprint = 0069 ED69 EABB DF84 5983 AD3C 6C20 BEFD 8109 03CB
>
> _______________________________________________
> Ntop-misc mailing list
> Ntop-misc [at] listgateway
> http://listgateway.unipi.it/mailman/listinfo/ntop-misc


jonschipp at gmail

Sep 29, 2011, 5:39 AM

Post #3 of 3 (345 views)
Permalink
Re: [PF_RING] can't use multiple applications on PF_RING device [In reply to]

Alfredo,

You were spot on, I had quick mode set to 1. It's now set to 0 and it works!
Thanks

On Wed, Sep 28, 2011 at 5:36 PM, Alfredo Cardigliano
<cardigliano [at] ntop>wrote:

>
> On Sep 28, 2011, at 11:21 PM, Jon Schipp wrote:
>
> Hello all,
>
> I have almost everything set up now. I spent all morning recompiling all my
> network monitoring tools to use pf_ring and the pf_ring libpcap.
> They all show up in /proc/net/pf_ring while running. yay!
>
> Though, I can't use more than one application on a single NIC (each NIC is
> PF_RING aware), I get a "pfring_set_channel_id() failed= -1" for any
> additional sniffing application.
> I'm running in transparent_mode 2 with the e1000 ring aware driver.
> Using PF_RING v5.0.1
> I need to run snort and ntop at all times.
>
>
> Jon
> you should be able to run both applications at the same time, unless you
> are using quick_mode.
> how did you load the kernel module?
>
> Alfredo
>
>
> Is this normal? I thought apps just read from the circular buffer, and
> there wasn't a limit. Maybe there is for transparent_mode 2?
> I looked through the User Guide, didn't find an answer.
>
> Any help is appreciated.
> Thanks
> --
> - Jon
> --
> ------------------------------------------------------------------
>
> VMB: 812-682-0231
>
> Dubois County Linux User Group - http://www.dclinux.org
> Southern Indiana Computer Klub - http://sickbits.networklabs.org
> Bloomington FOOLS - http://www.bloomingtonfools.org/
> BloomingLabs - http://www.bloominglabs.org
> ISSA-Kentuckiana - http://issa-kentuckiana.org
>
> GPG Key ID: 810903CB
> Key fingerprint = 0069 ED69 EABB DF84 5983 AD3C 6C20 BEFD 8109 03CB
>
> _______________________________________________
> Ntop-misc mailing list
> Ntop-misc [at] listgateway
> http://listgateway.unipi.it/mailman/listinfo/ntop-misc
>
>
>
> _______________________________________________
> Ntop-misc mailing list
> Ntop-misc [at] listgateway
> http://listgateway.unipi.it/mailman/listinfo/ntop-misc
>
>


--
- Jon
--
------------------------------------------------------------------

VMB: 812-682-0231

Dubois County Linux User Group - http://www.dclinux.org
Southern Indiana Computer Klub - http://sickbits.networklabs.org
Bloomington FOOLS - http://www.bloomingtonfools.org/
BloomingLabs - http://www.bloominglabs.org
ISSA-Kentuckiana - http://issa-kentuckiana.org

GPG Key ID: 810903CB
Key fingerprint = 0069 ED69 EABB DF84 5983 AD3C 6C20 BEFD 8109 03CB

NTop misc RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.