
Capturing to a Host CPU
Captured traffic can be sent to a host CPU through a libpcap library interface, where it can be made available to applications for analysis. A typical implementation provides IDS/Snort acceleration because of the hardware assist.
Figure 10 Capturing Matched Traffic via the libpcap Interface
| |||
tcpdump |
| Snort | Custom app |
|
| libpcap | |
SW |
|
|
|
|
|
| Matched Traffic |
HW | M1 | P1 | P0 M0 |
|
|
| Traffic to |
|
|
| monitor |
fn90035mp
Use the
Figure 11 Creating a Network Monitoring Solution with the P-Series
|
|
|
| ||
|
|
|
| Custom app | |
|
| libpcap |
| ||
SW |
|
|
|
| |
|
|
| Matched Traffic |
| |
HW | M1 | P1 | P0 M0 | Mgmt | |
Port | |||||
| |||||
|
|
| Traffic to | Custom | |
|
|
| security | ||
|
|
| monitor | ||
|
|
| monitoring | ||
|
|
|
| ||
|
|
|
| application |
fn90036mp
23 |