# bro cluster with pf ring dna+libzero

**URL:** <https://community.zeek.org/t/bro-cluster-with-pf-ring-dna-libzero/3157>\
**Category:** Zeek\
**Created:** [June 18, 2014, 11:02pm UTC](https://community.zeek.org/t/bro-cluster-with-pf-ring-dna-libzero/3157 "2014-06-18T23:02:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Li\_Yee\_Ting](https://avatars.discourse-cdn.com/v4/letter/l/ee59a6/32.png) [@Li\_Yee\_Ting](https://community.zeek.org/u/Li_Yee_Ting)\
**Post date:** [June 18, 2014, 11:02pm UTC](https://community.zeek.org/t/bro-cluster-with-pf-ring-dna-libzero/3157/1 "2014-06-18T23:02:07Z")

</div>

we're deploying a new bro cluster and am a huge newbie on all of this; so please excuse my ignorance. i have yet to actually start capturing on the cluster (awaiting delivery of a front-end device)

on each worker i have the dna+libzero ixgbe driver installed and insmodded. so i run:

$ sudo insmod pf\_ring.ko enable\_tx\_capture=0 min\_num\_slots=32768  
$ sudo insmod ixgbe.ko RSS=1,1,1,1 num\_rx\_slots=32768 mtu=9000

$ sudo /usr/sbin/setcap cap\_net\_raw,cap\_net\_admin=eip /usr/bin/pfdnacluster\_master  
$ /usr/bin/pfdnacluster\_master -d -P /var/run/pfdnacluster-dna0.pid -D bromaint -c 0 -i dna0 -n 10

i do the setcap as i am running bro as non-root user. looks good…

$ cat /proc/net/pf\_ring/13979-dna0.1  
Bound Device(s) :  
Active : 1  
Breed : DNA  
Sampling Rate : 1  
Capture Direction : RX+TX  
Socket Mode : RX only  
Appl. Name : dna-cluster-0-socket-0  
IP Defragment : No  
BPF Filtering : Disabled  
# Sw Filt. Rules : 0  
# Hw Filt. Rules : 0  
Poll Pkt Watermark : 128  
Num Poll Calls : 0  
Channel Id : 0  
Num RX Slots : 32768  
Num TX Slots : 8192  
Tot Memory : 672399360 bytes  
Cluster: Tot Recvd : 11  
Cluster: Tot Sent : 0

then on my manager i have the following nodes.cfg:

[manager]  
type=manager  
host=sec-broman

[proxy-0]  
type=proxy  
host=sec-broman

[proxy-1]  
type=proxy  
host=sec-broman

[sec-bro01-0]  
type=worker  
host=sec-bro01  
interface=dnacluster:0  
lb\_method=pf\_ring  
lb\_procs=10

using bro 2.3; so i believe the lb\_pf\_ring.py script understands the dnacluster interface spec.

so i do an 'broctl install' (as user bromaint) from the manager, then log onto my worker and run

$ sudo /usr/sbin/setcap cap\_net\_raw,cap\_net\_admin=eip /opt/bro/bin/capstats  
$ sudo /usr/sbin/setcap cap\_net\_raw,cap\_net\_admin=eip /opt/bro/bin/bro

then a 'broctl start' on the manager. everything looks fine so far… then i run 'broctl capstats' and i get:

Interface kpps mbps (10s average)

---

<div class="post-metadata">

**Author:** ![Gary\_Faulkner1](https://avatars.discourse-cdn.com/v4/letter/g/aeb1de/32.png) [@Gary\_Faulkner1](https://community.zeek.org/u/Gary_Faulkner1)\
**Post date:** [June 19, 2014, 12:27am UTC](https://community.zeek.org/t/bro-cluster-with-pf-ring-dna-libzero/3157/2 "2014-06-19T00:27:18Z")

</div>

Hello,

Capstats is a separate application as far as pfdnacluster\_master is concerned. You can tell pfdnacluster\_master that you want to send the same traffic to another application using the -n flag by using a "," and then specifying how many instances of the second app you intend to run. When you call pfdnacluster\_master try "-n 10,1" instead of "-n 10". You actually want to run two applications against the same traffic, but the second app, capstats, will only run one process that needs to consume all of the traffic instead of having slices of traffic load balanced between multiple processes.

Regards,  
Gary

---

<div class="post-metadata">

**Author:** ![Li\_Yee\_Ting](https://avatars.discourse-cdn.com/v4/letter/l/ee59a6/32.png) [@Li\_Yee\_Ting](https://community.zeek.org/u/Li_Yee_Ting)\
**Post date:** [June 19, 2014, 9:14pm UTC](https://community.zeek.org/t/bro-cluster-with-pf-ring-dna-libzero/3157/3 "2014-06-19T21:14:48Z")

</div>

Hi Gary,

ah, that makes sense! -n 10,1 works great 🙂 thanks very much.

is anyone using ZC pf\_ring for bro?

cheers,

Yee.

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [June 24, 2014, 4:25pm UTC](https://community.zeek.org/t/bro-cluster-with-pf-ring-dna-libzero/3157/4 "2014-06-24T16:25:45Z")

</div>

2.3 should support using the zc load balancing tool. If you follow the directions here:  
&nbsp;&nbsp;[http://bro.org/documentation/load-balancing.html](http://bro.org/documentation/load-balancing.html)

you should be able use the same config as for pf\_ring+DNA but you'll be sniffing an interface named zc:21 (or similar, the "21" is the cluster number that is auto assigned by broctl). One issue with the zbalance\_ipc tool that pf\_ring ships with though is that you can't load balance to multiple applications like you could with the older pfdnacluster\_master tool. I couldn't figure out how to do it at least.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:41pm UTC](https://community.zeek.org/t/bro-cluster-with-pf-ring-dna-libzero/3157/5 "2022-05-06T15:41:52Z")

</div>


