# Why does af-packet autofp runmode not support tpacket v3?

**URL:** https://forum.suricata.io/t/why-does-af-packet-autofp-runmode-not-support-tpacket-v3/5133
**Category:** Help
**Tags:** centos, suricata
**Created:** [December 12, 2024, 5:53am UTC](https://forum.suricata.io/t/why-does-af-packet-autofp-runmode-not-support-tpacket-v3/5133 "2024-12-12T05:53:03Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![gongziw](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/gongziw/32/3323_2.png) [@gongziw](https://forum.suricata.io/u/gongziw)
#### Post date: [December 12, 2024, 5:53am UTC](https://forum.suricata.io/t/why-does-af-packet-autofp-runmode-not-support-tpacket-v3/5133/1 "2024-12-12T05:53:03Z")

</div>

> Please include the following information with your help request:
> 
> - Suricata version  
> Suricata version 7.0.0 RELEASE
> - Operating system and/or Linux distribution  
> CentOS Linux release 7.9
> - How you installed Suricata (from source, packages, something else)  
> source

Hello there,

When I set Suricata’s af-packet autofp mode to tpacket v3, the following error is displayed:  
**“tpacket v3 is only implemented for ‘workers’ runmode. Switching to tpacket v2”.**  
I would like to know the design reasons why this mode does not support tpacket v3 ?

---

<div class="post-metadata">

### Author: ![Andreas\_Herz](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/andreas_herz/32/52_2.png) [@Andreas\_Herz](https://forum.suricata.io/u/Andreas_Herz)
#### Post date: [December 12, 2024, 8:22am UTC](https://forum.suricata.io/t/why-does-af-packet-autofp-runmode-not-support-tpacket-v3/5133/2 "2024-12-12T08:22:08Z")

</div>

Please provide more details, how does your `suricata.yaml` look like, what kernel is used, what NIC etc.  
What runmode do you run, instead of workers?

---

<div class="post-metadata">

### Author: ![gongziw](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/gongziw/32/3323_2.png) [@gongziw](https://forum.suricata.io/u/gongziw)
#### Post date: [December 12, 2024, 9:58am UTC](https://forum.suricata.io/t/why-does-af-packet-autofp-runmode-not-support-tpacket-v3/5133/3 "2024-12-12T09:58:37Z")

</div>

1. suricata.yaml af-packet config:

```auto
af-packet:
  - interface: eth0
    cluster-id: 99
    cluster-type: cluster_flow
    defrag: yes
    use-mmap: yes
    tpacket-v3: yes
    checksum-checks: no

```

1. kernel version

```auto
3.10.0-1160.el7.x86_64

```

3.NIC

```auto
driver: virtio_net
version: 1.0.0

```

1. suricata run command

```auto
suricata -c suricata.yaml -i eth0 --runmode autofp

```

I would like to understand the reasoning behind the logic design in the `ParseAFPConfig` function within the `runmode-af-packet.c` file of the Suricata source code. I couldn’t find any related documentation explaining it.

```auto
if (ConfGetChildValueBoolWithDefault(if_root, if_default, "tpacket-v3", (int *)&boolval) == 1) {
        if (boolval) {
            if (strcasecmp(RunmodeGetActive(), "workers") == 0) {
#ifdef HAVE_TPACKET_V3
                SCLogConfig("%s: enabling tpacket v3", aconf->iface);
                aconf->flags |= AFP_TPACKET_V3;
#else
                SCLogWarning("%s: system too old for tpacket v3 switching to v2", iface);
                aconf->flags &= ~AFP_TPACKET_V3;
#endif
            } else {
                SCLogWarning("%s: tpacket v3 is only implemented for 'workers' runmode."
                             " Switching to tpacket v2.",
                        iface);
                aconf->flags &= ~AFP_TPACKET_V3;
            }
        } else {
            aconf->flags &= ~AFP_TPACKET_V3;
        }
    }

```

---

<div class="post-metadata">

### Author: ![Andreas\_Herz](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/andreas_herz/32/52_2.png) [@Andreas\_Herz](https://forum.suricata.io/u/Andreas_Herz)
#### Post date: [December 12, 2024, 10:23am UTC](https://forum.suricata.io/t/why-does-af-packet-autofp-runmode-not-support-tpacket-v3/5133/4 "2024-12-12T10:23:33Z")

</div>

I would recommend the runmode workers which has a better performance, autofp is more of a fallback, thus the focus is on the worker runmode.

Also make sure to run a newer kernel 3.10 is over 10 years old.

---

<div class="post-metadata">

### Author: ![vjulien](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/vjulien/32/4_2.png) [@vjulien](https://forum.suricata.io/u/vjulien)
#### Post date: [December 12, 2024, 1:16pm UTC](https://forum.suricata.io/t/why-does-af-packet-autofp-runmode-not-support-tpacket-v3/5133/5 "2024-12-12T13:16:32Z")

</div>

Not supporting v3 for autofp allows us to avoid some threading overhead. If you use autofp, performance is clearly not a major concern, so using v2 is fine.

---

<div class="post-metadata">

### Author: ![gongziw](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/gongziw/32/3323_2.png) [@gongziw](https://forum.suricata.io/u/gongziw)
#### Post date: [December 13, 2024, 1:48am UTC](https://forum.suricata.io/t/why-does-af-packet-autofp-runmode-not-support-tpacket-v3/5133/6 "2024-12-13T01:48:17Z")

</div>

Yes, thank you very much. I just want to confirm whether it is technically feasible for Suricata’s af-packet autofp mode to operate based on tpacket v3.

---

<div class="post-metadata">

### Author: ![vjulien](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/vjulien/32/4_2.png) [@vjulien](https://forum.suricata.io/u/vjulien)
#### Post date: [December 13, 2024, 8:56am UTC](https://forum.suricata.io/t/why-does-af-packet-autofp-runmode-not-support-tpacket-v3/5133/7 "2024-12-13T08:56:08Z")

</div>

Support could be added, but it would require code changes. We are not planning to do it.

---

<div class="post-metadata">

### Author: ![gongziw](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/gongziw/32/3323_2.png) [@gongziw](https://forum.suricata.io/u/gongziw)
#### Post date: [December 13, 2024, 9:19am UTC](https://forum.suricata.io/t/why-does-af-packet-autofp-runmode-not-support-tpacket-v3/5133/8 "2024-12-13T09:19:11Z")

</div>

Thank you for your answer, it solved my question.
