Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

How to turn off promiscuous mode on a NIC?

Posted on 2004-04-27
7
Medium Priority
?
2,298 Views
Last Modified: 2012-06-21
My boss is getting tons of traffic going through his NIC, and would like it to stop. I have determined that his card is most likely running in promiscuous mode and is accepting all the packets thaqt come through the network. How do I turn this off? I can't find the option anywhere.

He is using Windows 2000

Thanks.
0
Comment
Question by:StickyDragon
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 7

Expert Comment

by:magus123
ID: 10929868
0
 
LVL 11

Expert Comment

by:PennGwyn
ID: 10931991
What tool is claiming that there are lots of packets coming through?

What does the network infrastructure look like (hubs, switches, etc)?
0
 

Author Comment

by:StickyDragon
ID: 10932127
This is when you right-click the LAN connection and choose "Status" from the drop-down.
0
Looking for a new Web Host?

Lunarpages' assortment of hosting products and solutions ensure a perfect fit for anyone looking to get their vision or products to market. Our award winning customer support and 30-day money back guarantee show the pride we take in being the industry's premier MSP.

 
LVL 2

Expert Comment

by:dramatix01
ID: 10934047
From the little bit of information that you have given it is very difficult to truly determine what the problem is.  It sounds like you are trying to treat the symptom and not the problem.

If you could answer some of the following questions we may be better able to help you:

1. How big is your network?
2. As PennGwyn asked, what type of network hardware are you using? (switches, hubs, etc.)
3. How old is the hardware attached to your network?

You can see where I'm going with this.  Any other information that you could offer would make this problem much easier to solve.

You may also want to stick a sniffer on your network to see if you have a chattering NIC or an employee that loves to watch or listen to streaming media while working.

Regards,
Dave...
0
 
LVL 1

Accepted Solution

by:
axelt earned 90 total points
ID: 10936534
NIC's don't just turn on promiscous mode by themselves - check for viruses.

If you want to know where the traffic is coming from, download ethereal from http://www.ethereal.com/distribution/win32/
Install winpcap3.0 from the same location before installing ethereal.

When capturing - turn promiscous mode off. Stop all applications.
If you use hubs - buy switches






0
 

Author Comment

by:StickyDragon
ID: 10941338
Definitely no viruses, we have Norton corporate, up to date definitions. Tried Ethereal. Neat program, seems that my boss is getting mostly TCP packets (whereas as I get TCP/UCP/ARP pretty evenly (And IPX for some reason, even though it isn't used). He seems to have a lot of TCP traffic coming from the Exchange server for one, and I don't for some reason. Why would this traffic be sent to one PC and not another?

1. We have about 150-200 computers
2. We have switches and hubs (all 3com rack-mount ones), but we are all connected into the same hub.... I did however move him to a switch and he had the same problem still.
0
 

Author Comment

by:StickyDragon
ID: 10942402
Turns out it was nothing more than a driver issue with 3Com 3C920 cards! Update your drivers if you ever run into this problem.
0

Featured Post

Simplify Your Workload with One Tool

How do you combat today’s intelligent hacker while managing multiple domains and platforms? By simplifying your workload with one tool. With Lunarpages hosting through Plesk Onyx, you can:

Automate SSL generation and installation with two clicks
Experience total server control

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question