Solved

A router/switch with a port that receives ALL packets

Posted on 2007-11-20
7
466 Views
Last Modified: 2010-08-05
I've heard that they make routers and/or switches that have a special port on them that recieves ALL network traffic.  THis would be for using with a packet sniffer.  Does anyone know of an inexpensive router/switch with this type of port?  What is this type of port called?

Also, anyone recommend an inexpensive software that will monitor all network traffic when connected to this port?

Bottom line:  I need a router/switch with a "receive all" port and some software...cheap.  (yeah, right)
0
Comment
Question by:markefaris
  • 4
  • 2
7 Comments
 
LVL 16

Assisted Solution

by:grahamnonweiler
grahamnonweiler earned 175 total points
Comment Utility
If all you want to do is monitor traffic on your network then you don't need to change your router - just download and install Wireshark (free) on to one of your internal machines then let it monitor whats going on on your network.

Wireshark a recognised network traffic analyzer and will report on all traffic/ports/protocols in the same subnet as the monitoring machine. Nothing else to add to your existing network and far easier than installing a managed router with monitoring firmware!

For more information and download: http://www.wireshark.org/
0
 
LVL 15

Accepted Solution

by:
getzjd earned 325 total points
Comment Utility


You need a switch that supports what is called "port mirroring "
You did not state how many port you need so it is hard to make a recommendation.

Here is a short list of switches http://www.effetech.com/sniffer/faq.htm

Tcpdump, WinDump, and Ethereal are 3 open source sniffers you can use.
0
 
LVL 15

Expert Comment

by:getzjd
Comment Utility
You cannot simply just use wireshark in a switched environment.  If you have a hub, then go for it.  Otherwise you need a switch that supports port mirroring
0
Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 15

Expert Comment

by:getzjd
Comment Utility
If you use wireshark in a switched environment with no port mirroring then all you see is your PC traffic and broacasts
0
 
LVL 16

Expert Comment

by:grahamnonweiler
Comment Utility
"If you use wireshark in a switched environment with no port mirroring then all you see is your PC traffic and broadcasts" - this is not strictly correct as the ability of Wireshark to see network traffic is dependent on the type of NIC in place on the monitoring PC  and whether you are in a "managed" or "un-managed" environment.
0
 
LVL 15

Expert Comment

by:getzjd
Comment Utility
You basically stated what I already stated.  Managed or unmanaged is no different that saying a switch that supports port mirroring and one that doesnt.   Yes your network card may not support it, but if it does and you are in a switched environment you need a switch that supports port mirroring  as well... period.   Port mirroring to my knoweldge is ONLY found on managed switches.  I would venture to say that not every single managed switched provides port mirroring...
0
 

Author Closing Comment

by:markefaris
Comment Utility
Thanks graham... for the wireshark link.
and thanks getzjd for recognizing that I was using a switch (which would not broadcast to all ports) and for the link of switches that have port mirroring (and for defining port mirroring).
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

New Server 172.16.200.2  was moved from behind Router R2 f0/1 to behind router R1 int f/01 and has now address 172.16.100.2. But we want users still to be able to connected to it by old IP. How to do it ? We can used destination NAT (DNAT).  In DNAT…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now