Solved

Internet traffice monitoring

Posted on 2013-11-13
6
376 Views
Last Modified: 2013-11-14
Dear Experts,

I've been asked by our CSO to produce a log for Internet browsing history of a particular employee without going onto his laptop.
I have downloaded Microsoft Network Monitor and WireShark, but not quite sure if I understand how to use them.
From what I can see, WireShark seems to be the right tool, but do I install that on the server, or can I run it from any client machine on the network?
Also, I think I need to use the filter, and I read their UserGuide, but it seems a bit confusing for someone like me, who is not experienced in network administration.
Please point me to the right direction.  thank you.
0
Comment
Question by:yballan
6 Comments
 
LVL 34

Expert Comment

by:Dan Craciun
ID: 39646267
The target connects to the network using wireless? Or he uses a wired connection?
0
 

Author Comment

by:yballan
ID: 39646272
He is using wired and static IP connection.
0
 
LVL 34

Expert Comment

by:Dan Craciun
ID: 39646289
Then you'll need to setup monitoring on the wire between his laptop and the router.
Wireshark is a good tool for this, but a bit overwhelming.

At a minimum, you'll need to filter packets by his IP (ip.addr == x.x.x.x), but you'll pick up a lot of extra traffic.

HTH,
Dan
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 
LVL 14

Accepted Solution

by:
comfortjeanius earned 250 total points
ID: 39646318
You can install it on your workstation and install the latest WinPcap on the remote workstation.  If you have Wireshark on the remote workstation then you do not have install WinPcap.

Now you will have to start the Remote Packet Capture Protocol or rpcapd service on the remote machine.

Start menu -----> type: cmd ----> Press Ctrl+Shift+Enter ---> click Yes to open the cmd with elevated privileges.

type:  sc \\<computername or IP address of remote machine> start rpcapd

Now you have to allow Port 2002 through your firewall.

Now start Wireshark from your workstation -----> Click on "Capture Options" -----> Manage Interfaces -----> Remote Interfaces ----> Add

Under Host: <your can enter the remote computer name or IP address
Under Port: 2002

Click on "Password authentication"
Username: administrator
Password: local administrator password

Click Apply

Click Close

Now on the Wireshark: Capture Options select the remote workstation check box and click Start

Now you are capturing all traffic from the remote workstation.


Here are some filters

Display the SNMP or DNS or ICMP traffics.
snmp || dns || icmp

ip.src == <ip address>


Port Range

(tcp[0:2] > 1500 and tcp[0:2] < 1550) or (tcp[2:2] > 1500 and tcp[2:2] < 1550)


tcp stream
tcp.stream eq 209

displays all retransmissions in the trace. Helps when tracking down slow application performance and packet loss

tcp.analysis.retransmission

Display all HTTP Request
http.request

Displays all TCP Rests
tcp.reset eq 1 or tcp.reset == 1

Set a conversation between the two define IP addresses
ip.addr == <ip address> && ip.addr == <ip address>

Display DHCP and the DORA process
bootp
0
 
LVL 3

Assisted Solution

by:Mintar
Mintar earned 250 total points
ID: 39647088
You need to setup a mirroring port in a manageable switch to monitor other computers.

This guide might be helpful(for cisco 2950):

http://www.imfirewall.us/support/WFilter_4_0/Doc/deploy_cisco2950.htm
0
 

Author Closing Comment

by:yballan
ID: 39647780
Thank you, Experts, for your guidance!
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
DHCP Server Service stops on SBS 2011 3 53
SHA2 certs for IIS AND Java? 2 77
Need to disable SSL Cipher 7 50
Problem to setup GUI 11 26
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

816 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now