Packet Capturing

Packet Capturing

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Packet Capturing Scooty 07-04-2008
Posted by Scooty on July 4, 2008, 2:43 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi all
I want to do some 'sniffing' on my network due to users reporting
speed issues on the LAN, I have PRTG installed but I am not seeing
anything unusual in the graphs to indicate high utilisation on the LAN
I have downloaded and installed Ethereal. On my system of course in a
switched network, I am seeing traffic over the wire, but it is only
traffic originating or destined for my IP and of course broadcast
traffic
I remember there was a way on a Cisco switch to set a port that
basically acts as a conduit for all traffic that passes over the
fabric
I want to set a system up to capture all data packets over the network
for analysis, if someone could tell me the best way to do this it
would be appreciated

Scott

Posted by Peter on July 4, 2008, 7:36 am
Hi Scott,

> I want to do some 'sniffing' on my network due to users reporting
> speed issues on the LAN, I have PRTG installed but I am not seeing
> anything unusual in the graphs to indicate high utilisation on the LAN
> I have downloaded and installed Ethereal. On my system of course in a
> switched network, I am seeing traffic over the wire, but it is only
> traffic originating or destined for my IP and of course broadcast
> traffic

You are looking for "Port Monitor mode". Its called different things
on different platforms but essentually that's what it is. Look under
your device specific documenation.

Cheers.....................pk.


--
Peter from Auckland.

Posted by News Reader on July 4, 2008, 4:00 pm
Scooty wrote:
> Hi all
> I want to do some 'sniffing' on my network due to users reporting
> speed issues on the LAN, I have PRTG installed but I am not seeing
> anything unusual in the graphs to indicate high utilisation on the LAN
> I have downloaded and installed Ethereal. On my system of course in a
> switched network, I am seeing traffic over the wire, but it is only
> traffic originating or destined for my IP and of course broadcast
> traffic
> I remember there was a way on a Cisco switch to set a port that
> basically acts as a conduit for all traffic that passes over the
> fabric
> I want to set a system up to capture all data packets over the network
> for analysis, if someone could tell me the best way to do this it
> would be appreciated
>
> Scott

The following is an example of Switch Port Analyzer (SPAN) on a Cisco 2950T:

e.g.:

monitor session 1 source interface Fa0/1
monitor session 1 destination interface Fa0/16 encapsulation dot1q


In this case I chose an inter-VLAN routing trunk port (Fa0/1) as the
SPAN source, and the Fa0/16 port as the SPAN destination. I used
"encapsulation dot1q" to preserve the 802.1Q headers, but that's optional.

As the other responder stated, you should consult the documentation for
your specific platform.

Best Regards,
News Reader

Similar ThreadsPosted
MDS 9216, capturing FC frames November 16, 2004, 9:26 pm
%PIX-4-402106: Rec'd packet not an IPSEC packet. August 25, 2006, 4:06 pm
UDP/IP packet question July 5, 2004, 6:58 am
802.1q for packet filtering April 4, 2005, 11:51 am
packet generator April 18, 2005, 5:45 pm
VPN Packet Size. April 23, 2005, 9:32 am
packet of disconnect August 7, 2005, 10:52 pm
Packet fragmentation April 25, 2006, 3:07 pm
pix 7.21 packet-tracer July 7, 2006, 6:53 am
Packet fragmentation July 27, 2006, 3:28 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map