with cisco switches you can designate a port for monitoring purposes
and it can receive all traffic for sniffing purposes. That's
how their intrusion detection sensor works.
On Wed, Mar 21, 2001 at 09:47:22AM -0600, Dustin Puryear wrote:
<em>> [EMAIL PROTECTED] wrote:
<em>> > 
<em>> > I want to play with a network packet sniffer for the
<em>> > first time and I was wondering if anybody had some
<em>> > previous experience or recommendations. The two I've
<em>> > heard of are sniffit and Ethereal.
<em>> 
<em>> sniffit is pretty cool. tcpdump is good for quick and dirty stuff.
<em>> 
<em>> > Ethereal has a number of dependencies :P and sniffit
<em>> > seems to be pretty much self contained, so I'm
<em>> > thinking of trying sniffit first.
<em>> > 
<em>> > Um, Dustin, does Vedalabs have a policy on packet
<em>> > sniffing? :)
<em>> 
<em>> Go for it. However, since we rely on switches and not hubs then you will
<em>> be very limited to what you can see. Aren't you on a hub over there in
<em>> your little cluster? You should be able to see everything on it, but not
<em>> past it unless it's traffic going to/from your cluster of machines.
<em>> 
<em>> I've read that it's possible to bump certain switches from switched hub
<em>> to shared hub mode if you swamp it. Not sure how accurate that is, but
<em>> if it worked you could see all traffic. Hmm, now if I catch you doing
<em>> that I'll kick your ass.
<em>> 
<em>> Regards, Dustin
<em>> 
<em>> > 
<em>> > John Hebert
<em>> > 
<em>> > __________________________________________________
<em>> > Do You Yahoo!?
<em>> > Get email at your own domain with Yahoo! Mail.
<em>> > http://personal.mail.yahoo.com/
<em>> > ================================================
<em>> > BRLUG - The Baton Rouge Linux User Group
<em>> > Visit http://www.brlug.net for more information.
<em>> > Send email to [EMAIL PROTECTED] to change
<em>> > your subscription information.
<em>> > ================================================
<em>> 
<em>> -- 
<em>> Dustin Puryear <[EMAIL PROTECTED]>
<em>> http://members.telocity.com/~dpuryear
<em>> In the beginning the Universe was created. 
<em>> This has been widely regarded as a bad move. - Douglas Adams
<em>> ================================================
<em>> BRLUG - The Baton Rouge Linux User Group
<em>> Visit http://www.brlug.net for more information.
<em>> Send email to [EMAIL PROTECTED] to change
<em>> your subscription information.
<em>> ================================================

-- 
Scott Harney<[EMAIL PROTECTED]>
 PGP Key fingerprint = 6D 31 C3 00 77 8C D1 C2 59 0A 01 E3 AF 81 94 63
================================================
BRLUG - The Baton Rouge Linux User Group
Visit http://www.brlug.net for more information.
Send email to [EMAIL PROTECTED] to change
your subscription information.
================================================

<!-- body="end" -->
<hr noshade>
<ul>
<li><strong>Next message:</strong> Scott Harney: "Re: [brluglist] recommend a 
good sniffer?"
<li><strong>Previous message:</strong> Dustin Puryear: "Re: [brluglist] HTML 
editor"
<li><strong>In reply to:</strong> Dustin Puryear: "Re: [brluglist] recommend a 
good sniffer?"
<li><strong>Next in thread:</strong> Scott Harney: "Re: [brluglist] recommend a 
good sniffer?"
<li><strong>Messages sorted by:</strong> 
[ date ]
[ thread ]
[ subject ]
[ author ]
[ attachment ]
</ul>
<hr noshade>

<small>
<em>
This archive was generated by hypermail 2.1.2 
: <em>Thu Sep 06 2001 - 11:10:51 CDT</em>
</em>
</small>
</body>
</html>

Reply via email to