Solved

A router/switch with a port that receives ALL packets

Posted on 2007-11-20
7
468 Views
Last Modified: 2010-08-05
I've heard that they make routers and/or switches that have a special port on them that recieves ALL network traffic.  THis would be for using with a packet sniffer.  Does anyone know of an inexpensive router/switch with this type of port?  What is this type of port called?

Also, anyone recommend an inexpensive software that will monitor all network traffic when connected to this port?

Bottom line:  I need a router/switch with a "receive all" port and some software...cheap.  (yeah, right)
0
Comment
Question by:markefaris
  • 4
  • 2
7 Comments
 
LVL 16

Assisted Solution

by:grahamnonweiler
grahamnonweiler earned 175 total points
ID: 20321697
If all you want to do is monitor traffic on your network then you don't need to change your router - just download and install Wireshark (free) on to one of your internal machines then let it monitor whats going on on your network.

Wireshark a recognised network traffic analyzer and will report on all traffic/ports/protocols in the same subnet as the monitoring machine. Nothing else to add to your existing network and far easier than installing a managed router with monitoring firmware!

For more information and download: http://www.wireshark.org/
0
 
LVL 15

Accepted Solution

by:
getzjd earned 325 total points
ID: 20321760


You need a switch that supports what is called "port mirroring "
You did not state how many port you need so it is hard to make a recommendation.

Here is a short list of switches http://www.effetech.com/sniffer/faq.htm

Tcpdump, WinDump, and Ethereal are 3 open source sniffers you can use.
0
 
LVL 15

Expert Comment

by:getzjd
ID: 20321783
You cannot simply just use wireshark in a switched environment.  If you have a hub, then go for it.  Otherwise you need a switch that supports port mirroring
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 15

Expert Comment

by:getzjd
ID: 20321792
If you use wireshark in a switched environment with no port mirroring then all you see is your PC traffic and broacasts
0
 
LVL 16

Expert Comment

by:grahamnonweiler
ID: 20321832
"If you use wireshark in a switched environment with no port mirroring then all you see is your PC traffic and broadcasts" - this is not strictly correct as the ability of Wireshark to see network traffic is dependent on the type of NIC in place on the monitoring PC  and whether you are in a "managed" or "un-managed" environment.
0
 
LVL 15

Expert Comment

by:getzjd
ID: 20321949
You basically stated what I already stated.  Managed or unmanaged is no different that saying a switch that supports port mirroring and one that doesnt.   Yes your network card may not support it, but if it does and you are in a switched environment you need a switch that supports port mirroring  as well... period.   Port mirroring to my knoweldge is ONLY found on managed switches.  I would venture to say that not every single managed switched provides port mirroring...
0
 

Author Closing Comment

by:markefaris
ID: 31410153
Thanks graham... for the wireshark link.
and thanks getzjd for recognizing that I was using a switch (which would not broadcast to all ports) and for the link of switches that have port mirroring (and for defining port mirroring).
0

Featured Post

Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

New Server 172.16.200.2  was moved from behind Router R2 f0/1 to behind router R1 int f/01 and has now address 172.16.100.2. But we want users still to be able to connected to it by old IP. How to do it ? We can used destination NAT (DNAT).  In DNAT…
I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question