# Using multiple interfaces standalone configuration

**URL:** <https://community.zeek.org/t/using-multiple-interfaces-standalone-configuration/7356>\
**Category:** Zeek\
**Created:** [May 14, 2024, 12:11pm UTC](https://community.zeek.org/t/using-multiple-interfaces-standalone-configuration/7356 "2024-05-14T12:11:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lcubics](https://avatars.discourse-cdn.com/v4/letter/l/ba9def/32.png) [@Lcubics](https://community.zeek.org/u/Lcubics)\
**Post date:** [May 14, 2024, 12:11pm UTC](https://community.zeek.org/t/using-multiple-interfaces-standalone-configuration/7356/1 "2024-05-14T12:11:43Z")

</div>

Hi all,

I know that this has been asked a few times already but I can’t find an answer to this question that actually works on my machine. Ill try to keep it short.

What would my node.cfg file look like if I want a standalone configuration to listen on multiple network interfaces installed on the same machine?

I have tried setting up a ‘local cluster’, used the -i flag to define multiple interfaces and tried to configure it using PFring parameters in the node.cfg file. Nothing seems to work so far. Maybe I did it wrong but I would like to know what the ‘official’ method would be to do this.

Any help would be much appreciated!

---

<div class="post-metadata">

**Author:** ![0x4A6F686E](https://avatars.discourse-cdn.com/v4/letter/0/b3f665/32.png) [@0x4A6F686E](https://community.zeek.org/u/0x4A6F686E)\
**Post date:** [May 14, 2024, 1:11pm UTC](https://community.zeek.org/t/using-multiple-interfaces-standalone-configuration/7356/2 "2024-05-14T13:11:03Z")

</div>

Hi,

we use multiple worker definitions in our node.cfg; see below.  
We use af\_packet instead of pf\_ring and have pinned the number of worker processess to specific CPU- cores. Next to that, we always rename our capture interfaces through udev rules to pcap0, pcap1, etc. to get a general configuration and don’t have to deal with the actual interfaces names as the will be different on different hardware setups. That is what you’ll see below.

[worker-1]  
type=worker  
host=localhost  
lb\_procs=28  
lb\_method=custom  
pin\_cpus=2,3,4,5,6,7,8,9,10,11,12,13,14,15,34,35,36,37,38,39,40,41,42,43,44,45,46,47  
interface=af\_packet::pcap0  
af\_packet\_fanout\_id=25  
af\_packet\_fanout\_mode=AF\_Packet::FANOUT\_QM  
af\_packet\_buffer\_size=134217728

[worker-2]  
type=worker  
host=localhost  
lb\_procs=28  
lb\_method=custom  
pin\_cpus=18,19,20,21,22,23,24,25,26,27,28,29,30,31,50,51,52,53,54,55,56,57,58,59,60,61,62,63  
interface=af\_packet::pcap1  
af\_packet\_fanout\_id=30  
af\_packet\_fanout\_mode=AF\_Packet::FANOUT\_QM  
af\_packet\_buffer\_size=134217728

Hope this helps.

Cheers, John

---

<div class="post-metadata">

**Author:** ![Lcubics](https://avatars.discourse-cdn.com/v4/letter/l/ba9def/32.png) [@Lcubics](https://community.zeek.org/u/Lcubics)\
**Post date:** [May 14, 2024, 2:18pm UTC](https://community.zeek.org/t/using-multiple-interfaces-standalone-configuration/7356/3 "2024-05-14T14:18:53Z")

</div>

Thanks John!

I have tried this worker approach and fixed some issues that I apparently did not notice earlier. _ **Cough** _ the zeek port was already in use _ **cough** _. Thanks to your config and my brain braining everything seems to work fine now!
