Re: A Few Questions related to Network Administration and TrafficAnalysis

From: Matt Florido (matt_at_floridonet.com)
Date: 03/07/05

  • Next message: Mike Klinke: "Re: Monitor 'refresh' problem"
    Date: Mon, 07 Mar 2005 06:56:13 -0800 (PST)
    To: fedora-list@redhat.com
    
    

    On Mon, March 7, 2005 1:27 am, Rebel said:
    [..]
    >
    > 2. Lets say I want to administer packets at the router
    > level and want to see which packet is going to which
    > machine (both to and fro), what tools/tips and
    > techniques are recommended for the same.
    >

    Check into tcpdump and ethereal. These are essentially packet capture
    programs, as is snort. You can add modules to the latter to make it an
    IDS.

    You want to make sure you're either on a promiscuous port on a switch, or
    connected to a hub. The reason being, switches don't typically repeat
    signals across all ports unless it has the ability to do so (higher end
    switches). Hubs are simply signal repeaters which means nodes connected
    to a hub sees packets/datagrams even though the destination is another
    node.

    -- 
    Regards,
    Matt Florido
    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Mike Klinke: "Re: Monitor 'refresh' problem"

    Relevant Pages

    • Re: suffering from poor network performance...
      ... Switches are smarter and often have external management interfaces, ... they keep track of each port individually in terms of speed and duplex ... broken traffic to all listeners the way a hub does, ... regenerating packet timing and permitting much larger topologies. ...
      (freebsd-net)
    • Re: Switch, Hub and Router
      ... What is the different between Switch, Hub and Router? ... Multiport repeater that forwards a packet to all ports, ... layer-4 switches, ... Routers connect networks. ...
      (microsoft.public.win2000.networking)
    • Re: A Few Questions related to Network Administration and TrafficAnalysis
      ... These are essentially packet capture ... > connected to a hub. ... The reason being, switches don't typically repeat ... And since you are running wireless connections don't forget kismet and ...
      (Fedora)
    • Re: Problems with MC9S12NE64 and some switches
      ... experiencing problems with certain network switches. ... losses when we connect the router to some switches, the packages gets ... I'd be inclined to put a packet sniffer on the network segment closest to ...
      (comp.arch.embedded)
    • RE: Caching a sniffer
      ... But you have wire speed layer 2 switches, ... to forward the packet to the correct port. ... If Cisco's port security is enabled, ... disrupting the entire network for 30 ...
      (Security-Basics)