That sniffer stuff..

Vegito

Diamond Member
Oct 16, 1999
8,329
0
0
I guess it's time for me to get into network sniffering...

basically I like to know how much and where the traffic on our LAN..

so I have 7 routers, each router goes to a different place

I'm assumsing I can use any sniffer program and see where everyone is hitting ?

Know any good ones besides the MS one ? thanks
 

ScottMac

Moderator<br>Networking<br>Elite member
Mar 19, 2001
5,471
2
0
NAI Sniffer Pro does a great job for a non-dedicated system. In the Linux environment, Ethereal seems to be pretty popular.

Remember, if you connect to a switch, you either have to tell the switch to "mirror" the traffic from the designated port to the port being montiored, or connect an intermediate HUB. Since switches work as point-to-point connections (bridges), the only traffic you'd see from a non-mirrored port would be broadcasts and multicasts (and traffic sent specifically to the monitoring machine).

So, if the switch doesn't support port mirroring (whatever that particular switch manufacturer calls that function), connect a crossover cable between the switch and a small hub, then a straight-through from the hub to the router (or wherever). Then plug the analyzer into the same hub, and you can monitor the traffic on that link.

Good Luck

Scott
 

Z_Amon

Member
Oct 10, 1999
122
0
0
Ethereal is also available as a Win32 program - I use it on my laptop for demonstration and portable network testing. Highly recommended as a freeware program, but remember to have a decent processor and a good chunk of RAM to play with (My rig is a 700 with 256 MB running Win2k).

If you can spend money, WildPackets' Etherpeek is on the cheaper end, then you can move up to the really expensive stuff. Entirely IMO, try Ethereal, and if you find that you really need a sniffer- and you figure out how to use it effectively - consider Etherpeek or one of its competitors. I believe there's a demo on the Wildpackets site, but most people who have used it aren't happy with the demo - their traffic goes past the demo buffer inside of a few seconds on larger networks. (oops).

Z.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
ethereal is the only one I really bother with. tcpdump for more simple things though.
 

wuboy

Member
Feb 28, 2002
59
0
0


<< Ethereal is also available as a Win32 program - I use it on my laptop for demonstration and portable network testing. Highly recommended as a freeware program, but remember to have a decent processor and a good chunk of RAM to play with (My rig is a 700 with 256 MB running Win2k). >>



How can you get Ethereal to work on win32? i installed it, and additionally, i had to install something called winpcap which is required for the program to run.

the problem i have with it is that it doesnt let me select an interface to capture. at the dropdown, the list is empty.

i havent tried yet on my linux box, but will do that later...

thanks all for all your help!

Z - i would like to ask you more about network security info, but ur email isnt listed in ur profile... would it be ok to let me contact you? thanks!
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0


<<

<< Ethereal is also available as a Win32 program - I use it on my laptop for demonstration and portable network testing. Highly recommended as a freeware program, but remember to have a decent processor and a good chunk of RAM to play with (My rig is a 700 with 256 MB running Win2k). >>



How can you get Ethereal to work on win32? i installed it, and additionally, i had to install something called winpcap which is required for the program to run.
>>



Winpcap is the Win32 port of libpcap.



<< the problem i have with it is that it doesnt let me select an interface to capture. at the dropdown, the list is empty. >>



I havent tried it on a Windows machine, but maybe Ill play with it later today.



<< i havent tried yet on my linux box, but will do that later... >>



Its pretty simple and a great tool.



<< Thanks all for all your help!

Z - i would like to ask you more about network security info, but ur email isnt listed in ur profile... would it be ok to let me contact you? thanks!
>>



You can pm me with some questions or post a thread if it is appropriate for this forum.
 

Vegito

Diamond Member
Oct 16, 1999
8,329
0
0
i dl ethereal.. cool.. i actually have a new spanking dual 1.26 ghz w/1gb memory..

will be playing soon
 

Z_Amon

Member
Oct 10, 1999
122
0
0
Erp...*laugh* I thought it was enabled. It's back in the profile again, sorry about that. Please feel free to contact me, if I can answer I will.

wuboy, it sounds like Ethereal isn't able to detect your NIC - what sort of NIC are you using? I've had good luck with 3Com 3c905b and Intel NICs, but I haven't tried it on some of the more generic ones. It also might be a bad Winpcap install, you might try removing it, rebooting, then reinstalling the newest version.

Again, sorry about the profile thing, my mistake!

Z.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |