Rate This ProjectLogin To Rate This Project
I use RCDCap to terminate an ERSPAN. It listens on a PF_RING-enabled interface, and the interface the network security apps listen on is PF_RING-enabled. It's high-performance, and does not seem to be dropping packets or overflowing buffers. I had to modify the build files a bit to get it to use a later version of the Boost libraries (1.55), and again to link it to the static pfring library, but it all worked in the end. It would be nice to see the ability to just strip vlan tags as well as filter traffic based on BPF rules. I've dug into the code a little, and it seems to be well designed and easily extensible, though, so I will try to give it a shot.