# \#943: PF\_Ring plugin to support load balancing while sniffing multiple interfaces

**URL:** <https://community.zeek.org/t/943-pf-ring-plugin-to-support-load-balancing-while-sniffing-multiple-interfaces/2660>\
**Category:** Development\
**Tags:** development\
**Created:** [April 26, 2013, 5:08pm UTC](https://community.zeek.org/t/943-pf-ring-plugin-to-support-load-balancing-while-sniffing-multiple-interfaces/2660 "2013-04-26T17:08:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![William\_Jones](https://avatars.discourse-cdn.com/v4/letter/w/8dc957/32.png) [@William\_Jones](https://community.zeek.org/u/William_Jones)\
**Post date:** [April 26, 2013, 5:08pm UTC](https://community.zeek.org/t/943-pf-ring-plugin-to-support-load-balancing-while-sniffing-multiple-interfaces/2660/1 "2013-04-26T17:08:40Z")

</div>

I read from multiple interfaces per worker, a consequence of of using taps to monitor a two port 10 GigE LACP pair. The net

I can't use PF\_ring sense bro does not synchronizes the start up of each worker. Sterilized the startup it would allow a single work to get same has function for each interface. The a good chanes that a worker could end up with hash function in pf\_Ring that are not the same.

Here is what my worker config look like:

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [April 26, 2013, 5:40pm UTC](https://community.zeek.org/t/943-pf-ring-plugin-to-support-load-balancing-while-sniffing-multiple-interfaces/2660/2 "2013-04-26T17:40:03Z")

</div>

This is fixing a different problem. People have been having trouble monitoring two separate links that don't see split routing. The problem you're encountering is something that most people have been fixing by merging the traffic streams before sending them into the analysis box with a separate piece of hardware (it would typically get load balanced at the same time too).

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![William\_Jones](https://avatars.discourse-cdn.com/v4/letter/w/8dc957/32.png) [@William\_Jones](https://community.zeek.org/u/William_Jones)\
**Post date:** [April 26, 2013, 6:23pm UTC](https://community.zeek.org/t/943-pf-ring-plugin-to-support-load-balancing-while-sniffing-multiple-interfaces/2660/3 "2013-04-26T18:23:10Z")

</div>

I understand what problem was fixed. I was hoping that some in the bro group would recognize that there are more problems with pf\_ring and bro that the current set of problems being talked about.

I merged packet streams before and found that method didn't solve my drop packet problems. What did was allocating enough packet space in the kernel per interface and having bro read from each interface.

Right now I am monitoring 2 10 GigE lacp pair. I about to put a system so that I can monitor a 4 10 GigE lacp set up.

You really should investigate what it takes keep up with multiple 10 GigE interfaces lacp interaces. You might come to the different conclusion the usefulness merging interface in the kernel kernel.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:40pm UTC](https://community.zeek.org/t/943-pf-ring-plugin-to-support-load-balancing-while-sniffing-multiple-interfaces/2660/4 "2022-05-06T15:40:57Z")

</div>


