Subject: Re: packet capturing
To: Steve Bellovin <email@example.com>
From: Antti Kantee <firstname.lastname@example.org>
Date: 01/13/2004 23:50:28
On Tue Jan 13 2004 at 15:59:20 -0500, Steve Bellovin wrote:
> http://luca.ntop.org/Ring.pdf gives some interesting insights into
> packet capture architectures. I knew that stock systems didn't do very
> well; I'm astonished at how poorly they do at monitoring a network.
Yes, indeed. I've been using pcap for an application on a fairly loaded
network on linux for some time now. It's good to know it shouldn't work
as well as it does ;)
My guess is that the network load there is falling short of the lossage
threshold, although probably not by very much.
Interesting insights anyhow, thanks for the pointer.
Antti Kantee <email@example.com> Of course he runs NetBSD
"connoisseurs do not chill their malts."