Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Advanced » Scaleability of Snort

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Scaleability of Snort


Posted by uber on April 13, 2005 05:51:26

Hello all
I'm in the midst of trying to help a customer who is deploying Snort to monitor an internet connection that will....ahem.....push a metric *load of traffic to and from the Internet. Suffice it to say their firewalls have special high performance nics to handle the load.
My question is:
1. Are there any rough "rule of thumbs" of how much thruput (in megs/sec) Snort can handle before it goes tits up. Just so you know I'm currently studying Snort optimization strategies...I'm just trying to find a rough performance ceiling here.
2. Since Snort is a stateful packet inspector, it must keep some kind of state table. Can the size of this state table be tweaked? Any caveats on this? Where can I look to grok the granular config details?
Thanks all!