Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 25 Mar 2006 07:07:36 -0500
From:      Chuck Swiger <cswiger@mac.com>
To:        Phil Regnauld <regnauld@catpipe.net>
Cc:        Paul Haddad <paul.haddad@gmail.com>, freebsd-net@freebsd.org
Subject:   Re: Non dropping packet monitor
Message-ID:  <44253288.4030700@mac.com>
In-Reply-To: <20060325091619.GA96723@moof.catpipe.net>
References:  <944074f30603241446i33f5eb26p187b2d7ff23d73de@mail.gmail.com> <A636D985-E160-46D1-B6EA-4C868B7A88AF@mac.com> <20060325091619.GA96723@moof.catpipe.net>

next in thread | previous in thread | raw e-mail | index | archive | help
Phil Regnauld wrote:
> Charles Swiger (cswiger) writes:
>>> Any suggestions?  Is there some pcap option that I need to look at?
>> If your dumps will fit into a RAM disk, use that, otherwise you're  
>> presumably [1] going to be limited to how fast you can scribble the  
>> packets to your disks.  Figure out the fastest you can do that, and  
>> then use dummynet to limit your network bandwidth to what your system  
>> is capable of capturing...
> 
> 	I seem to remember that IPFlter has a facility for logging
> 	packets where it's possible to deny forwarding of packets
> 	if the process reading the logging socket has disappeared
> 	or isn't reading fast enough.  Am I wrong ?

I'm not sure.  :-)  If what you've suggested _is_ available, it would be a
better solution to the original problem....

-- 
-Chuck




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?44253288.4030700>