# Bro-2.5.2 and PF\_RING 6.7 not load balancing properly

**URL:** <https://community.zeek.org/t/bro-2-5-2-and-pf-ring-6-7-not-load-balancing-properly/5168>\
**Category:** Zeek\
**Created:** [January 30, 2018, 8:07pm UTC](https://community.zeek.org/t/bro-2-5-2-and-pf-ring-6-7-not-load-balancing-properly/5168 "2018-01-30T20:07:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lamps\_Jereme](https://avatars.discourse-cdn.com/v4/letter/l/82dd89/32.png) [@Lamps\_Jereme](https://community.zeek.org/u/Lamps_Jereme)\
**Post date:** [January 30, 2018, 8:07pm UTC](https://community.zeek.org/t/bro-2-5-2-and-pf-ring-6-7-not-load-balancing-properly/5168/1 "2018-01-30T20:07:29Z")

</div>

It appears PF\_RING is not properly load balancing between Bro instances. For example, I have a single Bro node with 5 bro procs. Every entry in http.log is duplicated 5 times (exact timestamp and all fields are identical except the UID). My conclusion is pf\_ring is not splitting the traffic and that all procs are seeing all the traffic.

**my node.cfg:**

[bro-worders]  
type=worker  
host=localhost  
interface=eth5  
lb\_method=pf\_ring  
lb\_procs=5

**pf\_ring was loaded with:**  
enable\_tx\_capture=0 min\_num\_slots=32768

**Bro is correctly linked to libpcap libraries:**  
ldd /usr/local/bro/bin/bro | grep pcap  
libpcap.so.1 =\> /opt/pfring-6.6/lib/libpcap.so.1 (0x00007effe684d000)

**pf\_ring info:**  
[root@bro-box]# cat /proc/net/pf\_ring/info  
PF\_RING Version : 6.7.0 (dev:9b0e7c81718edb0ff6d070793bc868e3c3456bd5)  
Total rings : 6  
Standard (non ZC) Options  
Ring slots : 32768  
Slot version : 16  
Capture TX : No [RX only]  
IP Defragment : No  
Socket Mode : Standard  
Cluster Fragment Queue : 0  
Cluster Fragment Discard : 0

I am not sure where to go from here. Does anyone have any suggestions?

Jereme Lamps​

---

<div class="post-metadata">

**Author:** ![Benjamin\_Wood](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@Benjamin\_Wood](https://community.zeek.org/u/Benjamin_Wood)\
**Post date:** [January 31, 2018, 3:49pm UTC](https://community.zeek.org/t/bro-2-5-2-and-pf-ring-6-7-not-load-balancing-properly/5168/2 "2018-01-31T15:49:11Z")

</div>

The default load balancing for bro pf\_ring is to use 4-tuple.

If you have a lot of asymmetric traffic (hot IP/port combo like a syslog or something), you’ll see some “buckets” with more packets.

You may want to try a different load balancing scheme as outlined here:  
[https://www.bro.org/sphinx/components/broctl/README.html#pfringclustertype](https://www.bro.org/sphinx/components/broctl/README.html#pfringclustertype)

---

<div class="post-metadata">

**Author:** ![Azoff\_Justin\_S](https://avatars.discourse-cdn.com/v4/letter/a/dec6dc/32.png) [@Azoff\_Justin\_S](https://community.zeek.org/u/Azoff_Justin_S)\
**Post date:** [January 31, 2018, 4:25pm UTC](https://community.zeek.org/t/bro-2-5-2-and-pf-ring-6-7-not-load-balancing-properly/5168/3 "2018-01-31T16:25:37Z")

</div>

You may be running into an issue that was recently fixed in broctl and will be resolved in the next release. Depending on the order you install things in, pf\_ring load balancing can end up disabled.

What does the following output for your host?

&nbsp;&nbsp;&nbsp;&nbsp;[root@bro-dev ~]# broctl config | grep pfring  
&nbsp;&nbsp;&nbsp;&nbsp;pfringclusterid = 21  
&nbsp;&nbsp;&nbsp;&nbsp;pfringclustertype = 4-tuple  
&nbsp;&nbsp;&nbsp;&nbsp;ringfirstappinstance = 0

if you have pfringclusterid set to 0, that's the problem that was just fixed. You can easily workaround that by adding

PFRINGClusterID = 21

to your /usr/local/bro/etc/broctl.cfg

Once that is there, a broctl deploy should get everything working.

---

<div class="post-metadata">

**Author:** ![Lamps\_Jereme](https://avatars.discourse-cdn.com/v4/letter/l/82dd89/32.png) [@Lamps\_Jereme](https://community.zeek.org/u/Lamps_Jereme)\
**Post date:** [February 6, 2018, 3:55pm UTC](https://community.zeek.org/t/bro-2-5-2-and-pf-ring-6-7-not-load-balancing-properly/5168/4 "2018-02-06T15:55:24Z")

</div>

Justin,

Your solution seems to have fixed it.

Thanks!

Jereme

&nbsp;&nbsp;&nbsp;&nbsp;\>  
&nbsp;&nbsp;&nbsp;&nbsp;\> It appears PF\_RING is not properly load balancing between Bro instances. For example, I have a single Bro node with 5 bro procs. Every entry in http.log is duplicated 5 times (exact timestamp and all fields are identical except the UID). My conclusion is pf\_ring is not splitting the traffic and that all procs are seeing all the traffic.  
&nbsp;&nbsp;&nbsp;&nbsp;  
&nbsp;&nbsp;&nbsp;&nbsp;You may be running into an issue that was recently fixed in broctl and will be resolved in the next release. Depending on the order you install things in, pf\_ring load balancing can end up disabled.  
&nbsp;&nbsp;&nbsp;&nbsp;  
&nbsp;&nbsp;&nbsp;&nbsp;What does the following output for your host?  
&nbsp;&nbsp;&nbsp;&nbsp;  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[root@bro-dev ~]# broctl config | grep pfring  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;pfringclusterid = 21  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;pfringclustertype = 4-tuple  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ringfirstappinstance = 0  
&nbsp;&nbsp;&nbsp;&nbsp;  
&nbsp;&nbsp;&nbsp;&nbsp;if you have pfringclusterid set to 0, that's the problem that was just fixed. You can easily workaround that by adding  
&nbsp;&nbsp;&nbsp;&nbsp;  
&nbsp;&nbsp;&nbsp;&nbsp;PFRINGClusterID = 21  
&nbsp;&nbsp;&nbsp;&nbsp;  
&nbsp;&nbsp;&nbsp;&nbsp;to your /usr/local/bro/etc/broctl.cfg  
&nbsp;&nbsp;&nbsp;&nbsp;  
&nbsp;&nbsp;&nbsp;&nbsp;Once that is there, a broctl deploy should get everything working.

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:45pm UTC](https://community.zeek.org/t/bro-2-5-2-and-pf-ring-6-7-not-load-balancing-properly/5168/5 "2022-05-06T15:45:32Z")

</div>


