[Bro-Dev] snaplen and drops

The linux kernel will enable Large Receive Offload on nic's that support it.   This allows the nic to present multiple contiguous tcp packets as one large packet to the kernel.  I hqve seen tcpdump report packet size of 24K on interfaces with MTU sizes of 1500 bytes when LRO is on.  

The only was to turn of this feature in linux righ now is to turn route forwarding on  and reboot.. 

> That's very weird.  It's abnormal to get packets > 1514, right?  Are
> you monitoring a link with a lot of jumbo packets?

Not at all, but iirc, the kernel reserves spaces for packets of size
snaplen, which means that with larger snaplen, less will fit into its

>  Something is wrong, as that small bandwidth shouldn't matter no
>  matter what the packet sizes are anyway.

Yeah, I'm thinking so too. Something's odd going on, need to look into
it more closely.

As long as other's aren't seeing similar problems with the default 65K
snaplen, I'm fine.


