check this:
* * Networking options * Packet socket (CONFIG_PACKET) [Y/m/n/?] Packet socket: mmapped IO (CONFIG_PACKET_MMAP) [Y/n/?] ?
CONFIG_PACKET_MMAP:
If you say Y here, the Packet protocol driver will use an IO mechanism that results in faster communication.
If unsure, say N. Packet socket: mmapped IO (CONFIG_PACKET_MMAP) [Y/n/?] y
Have you been thinking about using the Phil Wood's ringbuffered libpcap?
I don't know if it will help here, my experience in useing it with Snort is quite positive. The last version has also improved Linux statistics reports. I dont know if this apply to "normal" version too.
Best regards, Edin
Price, Jason wrote:
What type of link are you trying to monitor?
[...] - This is the TCPDUMP workers list. It is archived at http://www.tcpdump.org/lists/workers/index.html To unsubscribe use mailto:[EMAIL PROTECTED]
