To capture all internet traffic.
PC's and Servers > switch > [hub] > router > internet.
Plug sniffer (or ethereal) into the hub.
The sniffer will see all internet traffic in and out.
To capture all traffic to a specifc pc or server.
PC (or server)> [hub] > switch > router > internet.
Plug sniffer into the hub.
The sniffer will see all traffic in and out of the PC.
Note: Hubs run at half duplex so some issues can arise or dissappear.
If you have a manageable switch (Cisco Catalyst, Nortel 450, etc, you can do a "port monitor/mirror" to copy traffic to switch port.
The Cisco 4500 series switches support these commands to monitor ports and/or vlans. This box can suppot 2 concurrent monitor sessions.
!To monitor a vlan
monitor session 1 source vlan 1
monitor session 1 destination interface gi1/1
!
! To monitor a specific port
monitor session 2 source interface gi1/1
monitor session 2 destination interface gi1/2
The commands on a Cisco 3550 (IOS) are slightly different. Also, note that you may see duplicate of some traffic when monitoring vlans. Monitor vlans for general information and troubleshooting. Monitor ports for specific information like bandwith utilizaion and specific troubleshooting.
Helpful books.
Sniffer Pro Network Optimization and Troubleshooting Handbook , Shimonski.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.