Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort interrupts

    Scheduled Pinned Locked Moved IDS/IPS
    2 Posts 2 Posters 743 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      motionthings
      last edited by

      Is this normal behavior for Snort? (see attachment)
      You can see when I installed Snort. Before there were no interrupts.

      The only other package I have installed is pfBlockerNG-Dev

      Simon
      interrupts.png
      interrupts.png_thumb

      Intel Core i3, 8GB RAM, 2x Intel Gigabit NIC's.
      CURRENT network: https://cacoo.com/diagrams/1Fh6EcMdZLjGq3zj
      Planned network: https://cacoo.com/diagrams/y2rMw37kzlzcHzZy
      Read BOFH (Bastard Operator From Hell): http://bofh.ntk.net/BOFH/index.php

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        Snort puts monitored interfaces into promiscuous mode.  This could, I suppose, generate a few more NIC interrupts as the card will be processing all packets instead of just packets sent to its MAC address.

        Bill

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.