Solved

cisco router trace traffic

Posted on 2004-09-01
6
970 Views
Last Modified: 2013-12-07
dear sir , i have a cisco router 1601,
having ip address 82.116.136.76
my ip address is 82.116.136.77
i want to see all tcp and udp ports comming from 82.116.136.77 to the router .
thanks
0
Comment
Question by:skynoc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 15

Expert Comment

by:scampgb
ID: 11952814
Hi skynoc,

Sorry, I'm a little unclear as to what you want to achieve here.

Do you mean that you want to analyse the traffic coming from your PC to the router, what ports the router will accept traffic on, or something else.

Could you please explain a little more about what you're trying to achieve or find out?

Thanks
0
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 168 total points
ID: 11952817
You can use netflow or you can define an access list with a log.  Netflow will display all flows/conversations on the router, what port they are using, and how much data is being passed.  The access-list method will display all traffic matching the access list entries and send it to the log.

Netflow:

interface ethernet0
ip route-cache flow

router#show ip cache flow

Access List:

access-list 101 permit tcp 82.116.136.77 range 0 65535 any range 0 65535 log
access-list 101 permit udp 82.116.136.77 range 0 65535 any range 0 65535 log
access-list 101 permit ip any any

interface ethernet0
ip access-group 101 in

router#show log
0
 
LVL 1

Assisted Solution

by:clkemp
clkemp earned 166 total points
ID: 11952994
You can use 'debug ip packet detail dump' to see all packets.  This will use a lot of your routers resources.

I would recommend getting a laptop or pc and loading Ethereal (http://ethereal.com/) and capturing the packets with it.  You can setup a filter to capture just the source/destination you desire.  Use 'host 82.116.136.77' in the capture filter box.  Are you looking for something specific or do you just want to see the traffic?
0
 
LVL 6

Assisted Solution

by:JRaster
JRaster earned 166 total points
ID: 11958680
Another great monitoring tool is IRIS from EEYE.  
Http://www.eeye.com/iris
Just put in a cheap hub between the router and the rest of the network, hook your PC to the hub and you can see all traffic by IP address.  
Works awesome, and keeps capture logs.
0

Featured Post

PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question