LinuxQuestions.org
Register a domain and help support LQ
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
Search this Thread
Old 11-19-2010, 01:49 PM   #1
jpat1023
Member
 
Registered: Oct 2003
Location: USA
Distribution: Red Hat 9, Ubuntu 10; Windows Server 2003 and XP
Posts: 34

Rep: Reputation: 15
Question Linux box to Monitor Network Traffic only


Hello all,

I manage a small business network with about 35 users. We have a T1 line, going into a hardware firewall/router, and then into our main switch. I want to setup a box between the router and the switch to monitor all incoming and outgoing traffic.

We already have a spare server with two nics and ubuntu server 10.10 installed. I just want to place this computer inline between the router and switch to monitor traffic only. I don't wanna mess with iptables or anything else because all that is already handled elsewhere on the network. I just want an inline box to monitor traffic.

How can I go about doing this??

Thanks in advance for your time.
 
Old 11-19-2010, 02:17 PM   #2
TB0ne
Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 14,777

Rep: Reputation: 2614Reputation: 2614Reputation: 2614Reputation: 2614Reputation: 2614Reputation: 2614Reputation: 2614Reputation: 2614Reputation: 2614Reputation: 2614Reputation: 2614
Quote:
Originally Posted by jpat1023 View Post
Hello all,

I manage a small business network with about 35 users. We have a T1 line, going into a hardware firewall/router, and then into our main switch. I want to setup a box between the router and the switch to monitor all incoming and outgoing traffic.

We already have a spare server with two nics and ubuntu server 10.10 installed. I just want to place this computer inline between the router and switch to monitor traffic only. I don't wanna mess with iptables or anything else because all that is already handled elsewhere on the network. I just want an inline box to monitor traffic.

How can I go about doing this??

Thanks in advance for your time.
You've got several options. They depend on how far you want to go, and if you want other monitoring options as well.

First thing I'd check out if I was you, would be ntop (http://www.ntop.org/overview.html). Just does network monitoring. If you want to monitor other things (like disk, CPU, etc.), on other machines, check out Nagios, Munin, or Zenoss. They can not only monitor network traffic, but other machine stats too, and they can run in conjunction with ntop.
 
Old 11-19-2010, 02:55 PM   #3
sys64738
Member
 
Registered: May 2008
Location: NRW/Germany
Posts: 105

Rep: Reputation: 30
Hi
I am not quite sure about your intention. Please take no offense but I am not quite sure if it is a good idea to put a Linux system between Router and LAN.
1. How fast is your Linux box? Fast enough for routing or switching and monitoring?
2. How calm are "your" 35 users when something goes wrong?

I don't know your switch, but if it is a managed switch the switch it is maybe possible to monitor (mirror) the Router port to the second NIC of your Ubuntu system. Then you can have one NIC for your LAN and one NIC for monitoring.
If something goes wrong you only loose your monitoring not your net. In my eyes much safer.

You can use ntop, iptraf, tcpdump, wireshark whatever you want. It depends what you want to see.
 
Old 11-19-2010, 04:17 PM   #4
jpat1023
Member
 
Registered: Oct 2003
Location: USA
Distribution: Red Hat 9, Ubuntu 10; Windows Server 2003 and XP
Posts: 34

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by TB0ne View Post
You've got several options. They depend on how far you want to go, and if you want other monitoring options as well.

First thing I'd check out if I was you, would be ntop (http://www.ntop.org/overview.html). Just does network monitoring. If you want to monitor other things (like disk, CPU, etc.), on other machines, check out Nagios, Munin, or Zenoss. They can not only monitor network traffic, but other machine stats too, and they can run in conjunction with ntop.
Yea I know some about ntop, ethereal, etc......I guess my question is how will the machine pass all traffic from one nic to the other?? I just want the traffic running through the machine, it doesn't need to do any sort of routing as that is already takin care of elsewhere on the network.

Quote:
Hi
I am not quite sure about your intention. Please take no offense but I am not quite sure if it is a good idea to put a Linux system between Router and LAN.
1. How fast is your Linux box? Fast enough for routing or switching and monitoring?
2. How calm are "your" 35 users when something goes wrong?
The intention is to monitor all network traffic, specially web traffic.
Linux systems often function as a router themselves,and routing takes little resources from the computer. Besides that fact, the computer being used is a dual processor rack server with plenty of resources. I figure setting it up to simply monitor and capture traffic is perfectly viable.
Quote:
I don't know your switch, but if it is a managed switch the switch it is maybe possible to monitor (mirror) the Router port to the second NIC of your Ubuntu system. Then you can have one NIC for your LAN and one NIC for monitoring.
If something goes wrong you only loose your monitoring not your net. In my eyes much safer.
I like this idea, but our switch is not managed and has no mirror port....plus, the linux box will add much more functionality than simply mirroring traffic, the linux box will give me control over the traffic if I need it.


I basically want the linux box to be an inline trasparent traffic sniffer.
 
Old 11-19-2010, 05:29 PM   #5
never say never
Member
 
Registered: Sep 2009
Location: Indiana, USA
Distribution: SLES, SLED, OpenSuse, CentOS, ubuntu 10.10, OpenBSD, FreeBSD
Posts: 195

Rep: Reputation: 37
Best solution I can think of it to setup your linux box as a router. If you have good NICs and a fair box you can run some router software such as PFSense (actually based on FREEBSD), Smoothwall, or several other linux firewall routers that will allow you to do the monitoring you want . . .

If all you are wanting to do is monitor web traffic, you could setup a transparent proxy (squid) and just force all internet traffic through that.

I use PFSense as routers at three locations, with a fiber 1GB connection and I have no problems routing traffic at all. The trick is to use good gear. I run Squid set up with transparent proxy and lightsquid for reporting. (you can also filter logs yourself).

I have been using them for about 3 years with zero problems at three locations routing Fiber internet, 1GB LAN, and 2 T1s.
 
Old 11-19-2010, 07:12 PM   #6
user100
Member
 
Registered: Aug 2010
Posts: 64

Rep: Reputation: 0
You could use a network sniffer, software like dSniff or ngrep or the other very good softwares mentioned above.

If you manage to route or link the traffic to another computer "sideways" from your network like sys64738 mentioned than that would be best. But I'm not sure how you would do that exactly.

The first example would be easiest to create. Than you would just create a forward machine while it logs. And using iptables for that would be best, not to make a firewall but just send bulk traffic through (from eth card to eth card). Without blocking or modifying or whatever it. And of course sniff or log/analyze it.
 
  


Reply

Tags
monitor, network, router, traffic, web


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
To Monitor network Traffic siva19185 Linux - Newbie 6 06-28-2008 02:23 AM
Network traffic monitor Lzolcsi Linux - Server 9 05-07-2007 08:23 AM
Router box measuring network traffic pavlom Linux - Enterprise 1 01-04-2007 05:34 AM
LXer: Darkstat - Network Traffic Analyzer or Network Monitor LXer Syndicated Linux News 0 07-04-2006 08:33 AM
Network traffic monitor teeno Linux - Software 2 09-29-2003 09:18 AM


All times are GMT -5. The time now is 02:52 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration