Closed south-devel closed 3 years ago
It work fine with vanilla pf_ring. And I found that vanilla pf_ring noticed this
24/9/2019 -- 21:56:28 -
- Enabling zero-copy for ens1f0
Is this correct??? pf_ring zero-copy run with Standard Mode???(https://www.ntop.org/guides/pf_ring/thirdparty/suricata.html#standard-mode)
[root@localhost system]# PF_RING_FT_CONF=/etc/pf_ring/ft-rules.conf suricata --pfring-int=ens1f0 --pfring-cluster-id=99 --pfring-cluster-type=cluster_flow -c /etc/suricata/suricata.yaml -vvv
24/9/2019 -- 21:56:03 -
pf_ringcfg --list-interfaces command output is below.
[root@localhost src]# pf_ringcfg --list-interfaces
Name: ens1f2 Driver: igb [Running ZC]
Name: enp2s0f0 Driver: tg3
Name: enp2s0f1 Driver: tg3
Name: ens1f3 Driver: igb [Running ZC]
Name: ens1f0 Driver: igb [Running ZC]
Name: ens1f1 Driver: igb [Running ZC]
This does not look like directly related to ZC, it looks like a suricata issue
OS : CentOS Linux release 7.7.1908 kernel : 3.10.0-1062.el7.x86_64 Suricata : 4.1.4 RELEASE
I don't know this is pf_ring problem or a problem with Suricata. However, some of the errors that pf_ring causes, seem to skip some of the settings of the suricata.