Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

How to turn off promiscuous mode on a NIC?

Posted on 2004-04-27
7
Medium Priority
?
2,301 Views
Last Modified: 2012-06-21
My boss is getting tons of traffic going through his NIC, and would like it to stop. I have determined that his card is most likely running in promiscuous mode and is accepting all the packets thaqt come through the network. How do I turn this off? I can't find the option anywhere.

He is using Windows 2000

Thanks.
0
Comment
Question by:StickyDragon
7 Comments
 
LVL 7

Expert Comment

by:magus123
ID: 10929868
0
 
LVL 11

Expert Comment

by:PennGwyn
ID: 10931991
What tool is claiming that there are lots of packets coming through?

What does the network infrastructure look like (hubs, switches, etc)?
0
 

Author Comment

by:StickyDragon
ID: 10932127
This is when you right-click the LAN connection and choose "Status" from the drop-down.
0
Transaction-level recovery for Oracle database

Veeam Explore for Oracle delivers low RTOs and RPOs with agentless transaction log backup and transaction-level recovery of Oracle databases. You can restore the database to a precise point in time, even to a specific transaction.

 
LVL 2

Expert Comment

by:dramatix01
ID: 10934047
From the little bit of information that you have given it is very difficult to truly determine what the problem is.  It sounds like you are trying to treat the symptom and not the problem.

If you could answer some of the following questions we may be better able to help you:

1. How big is your network?
2. As PennGwyn asked, what type of network hardware are you using? (switches, hubs, etc.)
3. How old is the hardware attached to your network?

You can see where I'm going with this.  Any other information that you could offer would make this problem much easier to solve.

You may also want to stick a sniffer on your network to see if you have a chattering NIC or an employee that loves to watch or listen to streaming media while working.

Regards,
Dave...
0
 
LVL 1

Accepted Solution

by:
axelt earned 90 total points
ID: 10936534
NIC's don't just turn on promiscous mode by themselves - check for viruses.

If you want to know where the traffic is coming from, download ethereal from http://www.ethereal.com/distribution/win32/
Install winpcap3.0 from the same location before installing ethereal.

When capturing - turn promiscous mode off. Stop all applications.
If you use hubs - buy switches






0
 

Author Comment

by:StickyDragon
ID: 10941338
Definitely no viruses, we have Norton corporate, up to date definitions. Tried Ethereal. Neat program, seems that my boss is getting mostly TCP packets (whereas as I get TCP/UCP/ARP pretty evenly (And IPX for some reason, even though it isn't used). He seems to have a lot of TCP traffic coming from the Exchange server for one, and I don't for some reason. Why would this traffic be sent to one PC and not another?

1. We have about 150-200 computers
2. We have switches and hubs (all 3com rack-mount ones), but we are all connected into the same hub.... I did however move him to a switch and he had the same problem still.
0
 

Author Comment

by:StickyDragon
ID: 10942402
Turns out it was nothing more than a driver issue with 3Com 3C920 cards! Update your drivers if you ever run into this problem.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
This month, Experts Exchange’s free Course of the Month is focused on CompTIA IT Fundamentals.
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

581 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question