From owner-freebsd-net@FreeBSD.ORG Tue Jul 15 21:27:36 2008 Return-Path: Delivered-To: freebsd-net@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 61CAF1065675 for ; Tue, 15 Jul 2008 21:27:36 +0000 (UTC) (envelope-from julian@elischer.org) Received: from outS.internet-mail-service.net (outs.internet-mail-service.net [216.240.47.242]) by mx1.freebsd.org (Postfix) with ESMTP id 418AF8FC08 for ; Tue, 15 Jul 2008 21:27:36 +0000 (UTC) (envelope-from julian@elischer.org) Received: from idiom.com (mx0.idiom.com [216.240.32.160]) by out.internet-mail-service.net (Postfix) with ESMTP id 2F8F9246D; Tue, 15 Jul 2008 14:27:36 -0700 (PDT) Received: from julian-mac.elischer.org (localhost [127.0.0.1]) by idiom.com (Postfix) with ESMTP id B01872D600D; Tue, 15 Jul 2008 14:27:35 -0700 (PDT) Message-ID: <487D15C7.3040700@elischer.org> Date: Tue, 15 Jul 2008 14:25:27 -0700 From: Julian Elischer User-Agent: Thunderbird 2.0.0.14 (Macintosh/20080421) MIME-Version: 1.0 To: Robin Sommer References: <20080711202737.GB27418@icir.org> <487B5840.3000401@FreeBSD.org> <20080715212013.GA91123@icir.org> In-Reply-To: <20080715212013.GA91123@icir.org> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: freebsd-net@FreeBSD.org, "Bruce M. Simpson" Subject: Re: BPF problems on FreeBSD 7.0 X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 15 Jul 2008 21:27:36 -0000 Robin Sommer wrote: > On Mon, Jul 14, 2008 at 14:44 +0100, Bruce M. Simpson wrote: > >> One place to start might be: netstat -B output in 7.x (I *think* this got >> MFCed), this will let us see what the drop count is for the Bro process, >> and what the flags are for the open BPF descriptors in the system. > > Thanks for the suggestion. Here's the netstat -B output at the time > it has stalled (after about 6 hours of working normally): > > Pid Netif Flags Recv Drop Match Sblen Hblen Command > 14557 nxge0 p--s--- 2162189525 32514465 42815457 4194248 4194258 br the Recv number is JUST past 2^31. at your rate of receiving packets, it passed that value about 2 minutes before this snapshot was taken.. > > Top shows: > > PID USERNAME THR PRI NICE SIZE RES STATE C TIME WCPU COMMAND > 14557 bro 1 -58 0 272M 267M 5 25:53 0.00% bro > > > > A few minutes after starting the process, when Bro was still working > fine, a netstat -B output was: > > # netstat -B > Pid Netif Flags Recv Drop Match Sblen Hblen Command > 14557 nxge0 p--s--- 4779235 0 94967 0 0 bro > > Thanks, > > Robin >