In late March, Ivan Pepelnjak interviewed me on Software Gone Wild about ntop and ntopng, and in a second interview about PF_RING.
The main topic of the second interview have been:
- What is the difference between PF_RING and the Linux built-in packet capturing module;
- How can you process over 10 million packets per second per CPU core?
- Do you need special device drivers for PF_RING or can you use the standard Linux NIC drivers?
- How does a packet processing application interact with the PF_RING library?
- How do you spread packets across multiple cores, multiple copies of monitoring application, or even multiple monitoring applications?
You can read the whole interview and listen to the podcast. Enjoy!