Routing all packets to a specific NIC

Routing all packets to a specific NIC

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Routing all packets to a specific NIC adsaero 04-22-2007
Posted by adsaero on April 22, 2007, 11:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hey there - I have a Cisco 7206 running IOS 12.1, and I'm wondering if
there's a way to forward copies of all packets that pass thru the
router (or at least, through a specific interface) to another ethernet
interface on the router for use in network monitoring; I've got a
network analysis box that needs to see all the traffic in order to
analyze it.

I've ready online that it looks like I can do this, but I haven't been
able to figure out the concepts and the commands needed to do it. Can
anyone point me in the right direction?


Posted by J.Cottingim on April 23, 2007, 12:08 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> Hey there - I have a Cisco 7206 running IOS 12.1, and I'm wondering if
> there's a way to forward copies of all packets that pass thru the
> router (or at least, through a specific interface) to another ethernet
> interface on the router for use in network monitoring; I've got a
> network analysis box that needs to see all the traffic in order to
> analyze it.


The obvious solution would be to span the switch port the router
interface you want to monitor is connected to.


>
> I've ready online that it looks like I can do this, but I haven't been
> able to figure out the concepts and the commands needed to do it. Can
> anyone point me in the right direction?


Forward us (the internet community) a few of the links that you think
talks about what you want to do - This may help us better identify
your solution.


JC


Posted by adsaero on April 23, 2007, 12:31 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Well, here it is - from the Etherape documentation: (bashful)

]Why I see only the traffic to/from the EtherApe machine ?
]
]Probably you have a switched network. Unless all traffic goes thru
the etherape machine (or you have an hub), etherape sees local
traffic.
]Etherape can "see" only the traffic physically passing on the netcard
wire. Many small network use hubs to connect computers, so every
packet is
]ysically transmitted to every netcard.
]A larger network use combinations of switches and routers, sometimes
even firewalls to connect nodes, so your network card receives only
its own traffic or
]broadcast.
]To monitor an entire network you can enable analisys/roving mode on
your switch (essentially copies all traffic to a single port). If you
have multiple switches,
]or routers, or the total bandwith exceeds the port maximum, you still
will see only part of the traffic.
]If you only want to monitor internet traffic, a better solution is to
place etherape on the (internal) internet gateway.

Essentially, yes - all the equipment I want to monitor is on a
switch. If I can copy all IP traffic going through my WAN port to a
spare ethernet port on my router (note the idea is to copy it so as
not to disrupt the traffic). Essentially bridge the traffic from the
WAN port to the spare ethernet nic.




> > Hey there - I have a Cisco 7206 running IOS 12.1, and I'm wondering if
> > there's a way to forward copies of all packets that pass thru the
> > router (or at least, through a specific interface) to another ethernet
> > interface on the router for use in network monitoring; I've got a
> > network analysis box that needs to see all the traffic in order to
> > analyze it.
>
> The obvious solution would be to span the switch port the router
> interface you want to monitor is connected to.
>
>
>
> > I've ready online that it looks like I can do this, but I haven't been
> > able to figure out the concepts and the commands needed to do it. Can
> > anyone point me in the right direction?
>
> Forward us (the internet community) a few of the links that you think
> talks about what you want to do - This may help us better identify
> your solution.
>
> JC



Posted by J.Cottingim on April 23, 2007, 12:57 am
If you were  Registered and logged in, you could reply and use other advanced thread options

Assuming you only have one ethernet interface on the router hat the
traffic flows through, this would be very simple.
Span the switch port the router is connected to - to the switch port
that your Unix machine that's running EtherApe is on.

It's very easy for a switch to do this, and is more advisable than
bridging one interface to another "spare" interface on the router.

The commands you use to span the switch port varies based on the
version of code as well as the model of the switch. - so you'll have
to do some research.


-JC


Similar ThreadsPosted
redirect traffic on specific ip to specific interface June 3, 2005, 12:51 pm
monitor specific IP August 29, 2004, 3:53 pm
Block a specific file March 29, 2005, 12:46 pm
vpn problem at specific localtion July 17, 2005, 6:17 am
vpn problem at specific localtion July 17, 2005, 6:17 am
monitoring specific connections October 3, 2005, 11:08 am
PIX 501 access to specific IP question February 3, 2006, 8:56 am
Monitoring specific traffic. October 3, 2006, 3:31 am
switch port going up and down on specific NIC October 12, 2006, 9:47 am
ip helper for a specific address June 18, 2007, 4:21 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map