With the 3com 3300, in order to monitor the network traffic that is traversing the 3com 3300 switch, one must configure what is called a monitor port or analysis port (under the Roving Analysis Setup) using the 3com Switch Management Software. One has to define an Analysis port (the port that is connected to the Sniffer) and a monitor port (the port that is being monitored). Once the two are defined, and it is enabled via the Switch Management software, the stack passes all the traffic going in and out of the monitor port and copies it to the analysis port.
If you are attempting to monitor traffic across multiple VLANs, an analysis port must be setup in each VLAN used by the 3com 3300. Note: The analysis port should be configured to have a higher bandwidth than the monitor port, otherwise, not all traffic that is being analyzed will be captured entirely. /hope this helps /cheers, *useless memorization of switch/router configuration options.. * (these type of questions never appear on a CISSP exam.:-) /m At 11:53 AM 1/4/2002 -0800, William Stackpole wrote: >Daniel, > >Most switches will allow one or more ports to be combined or cross connected >for this very purpose. If this isn't possible then the best you can do is >put the sniffer on the backbone segment attached to the switch. You >wouldn't be able to see the traffic between individual switch nodes but you >will be conversations out to servers, Internet connections etc. The other >alternative, if this is a temporary situsation for troubleshooting purposes, >you could replace the switch with a hub. > >-- Bill Stackpole, CISSP > > >----- Original Message ----- >From: <[EMAIL PROTECTED]> >To: <[EMAIL PROTECTED]> >Sent: Friday, January 04, 2002 11:14 AM >Subject: (no subject) > > > > Hi, > > > > how do I use snnifer in a switch in a way that permits to capture all > > traffic ? (3com 3300) > > > > Thank's in advance, > > Daniel > > > > _______________________________________________ > > Firewalls mailing list > > [EMAIL PROTECTED] > > http://lists.gnac.net/mailman/listinfo/firewalls > >_______________________________________________ >Firewalls mailing list >[EMAIL PROTECTED] >http://lists.gnac.net/mailman/listinfo/firewalls _______________________________________________ Firewalls mailing list [EMAIL PROTECTED] http://lists.gnac.net/mailman/listinfo/firewalls
