[Oisf-users] Suricata in Intel's DPDK environment

Andreas Herz andi at geekosphere.org
Sat May 28 23:03:01 UTC 2016


On 16/05/16 at 12:44, Vishal Kotalwar V wrote:
> Hi, 
>
> I am planning to run suricata in Intel's DPDK framework. I intend to
> run as an IPS so probably I need to replace NFQ calls with DPDK
> library calls for packet receive and verdict out along with some
> memory management related calls; that is my top level view. 

Do you have a special reason why you want to go for DPDK?

> I know, this is not in Suricata's current road-map but would like to
> know if anybody has tried this or similar thing before. Your
> experience can help me a great way. Any advice or pointers in the
> direction are also welcome. 

I talked to a friend who has already done some DPDK related work.
It seems to be a lot of work with the API and Intel specific parts.

Since we have some Intel people working on hyperscan, there might
someone with more DPDK background knowledge and how it would fit into
Suricata.

> 
> Thanks & regards, Vishal V. Kotalwar 

> _______________________________________________
> Suricata IDS Users mailing list: oisf-users at openinfosecfoundation.org
> Site: http://suricata-ids.org | Support: http://suricata-ids.org/support/
> List: https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users
> Suricata User Conference November 9-11 in Washington, DC: http://oisfevents.net


-- 
Andreas Herz



More information about the Oisf-users mailing list