I wanted to share some knowledge I picked up when I ran into trouble using libpcap and snort to sniff a high-capacity (1 GB full duplex; 2 GB max aggregate) network link. The applications would sniff all traffic successfully, but would crash when the file size hit 2 GB captured.
If you're having issues with creating 2 GB files, even though you have a filesystem that supports it, and/or you know the kernel supports it, this is for you.