[Nolug] Packet sniffing on switched network

From: Chris Jones <techmaster_at_gmail.com>
Date: Fri, 1 Feb 2008 11:01:34 -0600
Message-ID: <945e1c690802010901x7d1a5f83n2d0cf0efe0d0f3f3@mail.gmail.com>

I have a client whose internet is running very slowly. I suspect that
there's a lot of traffic coming from somewhere, so I need to sniff the
traffic to figure out where it's coming/going. Problem is, this is a
switched network.

The network is a fairly typical setup, going like this:
internet -> dsl modem -> cisco pix -> linksys switch -> LAN

I can't find a way to get this linksys to go promiscuous, so I'm thinking
maybe I could set up some kind of machine with two nic's, and have it
forward all traffic from one nic to the other, and have the machine just
analyze all traffic as it passes through. Not sure if that's the best
route, or maybe one of you guys have run across a better option? If that is
the best way to go, does anyone know of a good free product to do this? Or
maybe I can somehow use SNMP to pull this info out of the pix? Any
suggestions?

___________________
Nolug mailing list
nolug@nolug.org
Received on 02/01/08

This archive was generated by hypermail 2.2.0 : 12/19/08 EST