[Bro] strange dropped packets issue

William L. Jones jones at tacc.utexas.edu
Wed Nov 4 07:39:25 PST 2009

I would remove the code.  

The change to libpcap was made years ago.   It won't break the really old system and would make it easier for bro install an new linux systems - you won't have to change the code by hand!

-----Original Message-----
From: bro-bounces at ICSI.Berkeley.EDU [mailto:bro-bounces at ICSI.Berkeley.EDU] On Behalf Of Seth Hall
Sent: Wednesday, November 04, 2009 8:45 AM
To: Robin Sommer
Cc: Justin Azoff; bro at ICSI.Berkeley.EDU
Subject: Re: [Bro] strange dropped packets issue

On Nov 3, 2009, at 6:40 PM, Robin Sommer wrote:
> On Tue, Nov 03, 2009 at 16:52 -0500, Justin Azoff wrote:
>> I think I'm running into some sort of libpcap issue on Linux, but  
>> I'm not sure.
> Any chance it's this?
>    http://tracker.icir.org/bro/ticket/18

Would it make sense to just remove the linux specific code?  Is anyone  
running older Linux distros for their analyzers?

Based on one of the links in the ticket, it looks like Debian updated  
their libpcap and got rid of this issue in 2005.


Seth Hall
Network Security - Office of the CIO
The Ohio State University
Phone: 614-292-9721

Bro mailing list
bro at bro-ids.org

More information about the Bro mailing list