Re: 「FOR HELP」The mirrored traffic i s heavily lost.
Richard Bejtlich <[email protected]> Tue, 29 Oct 2019 14:05:32 -0400
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CAOtSMjZnuBE8zr_qJoraHDDVfXyvPJ4QX_8SvkP05FqymqwBfg@mail.gmail.com> |
Hello, How are you mirroring the traffic? If it’s a switch span port, that could be the source of the dropped traffic. Sincerely, Richard On Tue, Oct 29, 2019 at 7:30 AM 杨毅凌 <[email protected]> wrote: > I mirrored the traffic between the core switch of our computer room and > the public network firewall, but the zeek report contained a lot of packet > loss (30%), and currently uses PFring for packet capture. I confirm that > the hardware is fully capable of handling these packet。"Capture loss" and > "dropped packets" have alarms。At the same time, in the werid log, a large > number of TCP_seq/ack_underflow_or_misorder logs are included. > So I want to know why there is such a high rate of packet loss, how to > trace the cause, and how to solve it.I look forward to receiving your reply. > _______________________________________________ > Zeek mailing list > [email protected] > http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek -- Richard Bejtlich Principal Security Strategist, Corelight https://corelight.blog/author/richardbejtlich/ _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek