Solved

cisco router trace traffic

Posted on 2004-09-01
6
948 Views
Last Modified: 2013-12-07
dear sir , i have a cisco router 1601,
having ip address 82.116.136.76
my ip address is 82.116.136.77
i want to see all tcp and udp ports comming from 82.116.136.77 to the router .
thanks
0
Comment
Question by:skynoc
6 Comments
 
LVL 15

Expert Comment

by:scampgb
ID: 11952814
Hi skynoc,

Sorry, I'm a little unclear as to what you want to achieve here.

Do you mean that you want to analyse the traffic coming from your PC to the router, what ports the router will accept traffic on, or something else.

Could you please explain a little more about what you're trying to achieve or find out?

Thanks
0
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 168 total points
ID: 11952817
You can use netflow or you can define an access list with a log.  Netflow will display all flows/conversations on the router, what port they are using, and how much data is being passed.  The access-list method will display all traffic matching the access list entries and send it to the log.

Netflow:

interface ethernet0
ip route-cache flow

router#show ip cache flow

Access List:

access-list 101 permit tcp 82.116.136.77 range 0 65535 any range 0 65535 log
access-list 101 permit udp 82.116.136.77 range 0 65535 any range 0 65535 log
access-list 101 permit ip any any

interface ethernet0
ip access-group 101 in

router#show log
0
 
LVL 1

Assisted Solution

by:clkemp
clkemp earned 166 total points
ID: 11952994
You can use 'debug ip packet detail dump' to see all packets.  This will use a lot of your routers resources.

I would recommend getting a laptop or pc and loading Ethereal (http://ethereal.com/) and capturing the packets with it.  You can setup a filter to capture just the source/destination you desire.  Use 'host 82.116.136.77' in the capture filter box.  Are you looking for something specific or do you just want to see the traffic?
0
 
LVL 6

Assisted Solution

by:JRaster
JRaster earned 166 total points
ID: 11958680
Another great monitoring tool is IRIS from EEYE.  
Http://www.eeye.com/iris
Just put in a cheap hub between the router and the rest of the network, hook your PC to the hub and you can see all traffic by IP address.  
Works awesome, and keeps capture logs.
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Join & Write a Comment

Suggested Solutions

Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
Viewers will learn how to properly install and use Secure Shell (SSH) to work on projects or homework remotely. Download Secure Shell: Follow basic installation instructions: Open Secure Shell and use "Quick Connect" to enter credentials includi…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now