LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-31-2009, 05:38 PM   #1
vasco2009
LQ Newbie
 
Registered: Feb 2009
Posts: 7

Rep: Reputation: 0
Question network monitoring with iptraf and port mirroring


hello everybody

i try to setup network monitoring server.
i have a server with two interfaces eth0 and eth1.
eth0 is set with default setings, and eth1 is connected to a mirrored port on my switch to catch all the traffic on my network.
but the problem is, when i start iptraf an i monitor eth1, i see only non-ip traffic, is that normal ?

config line for eth1 in /etc/network/interfaces

auto eth1
iface eth1 inet manual
up ifconfig $IFACE 0.0.0.0 up
up ip link set $IFACE promisc on
down ip link set $IFACE promisc off
down ifconfig $IFACE down

Thanks for your help.

Thomas
 
Old 06-01-2009, 10:22 AM   #2
janhe
Member
 
Registered: Jul 2007
Location: Belgium
Distribution: slackware64 14.2, slackware 13.1
Posts: 371

Rep: Reputation: 54
Which monitoring option are you using?

This is what is does with me:

LAN station monitor shows the ethernet addresses
IP traffic monitor shows the IP address and the port number
 
Old 06-02-2009, 08:48 AM   #3
vasco2009
LQ Newbie
 
Registered: Feb 2009
Posts: 7

Original Poster
Rep: Reputation: 0
i just use iptraf without options
 
Old 06-03-2009, 02:43 AM   #4
janhe
Member
 
Registered: Jul 2007
Location: Belgium
Distribution: slackware64 14.2, slackware 13.1
Posts: 371

Rep: Reputation: 54
don't you get a menu with options to choose from when you startup iptraf?

what do you see when you run iptraf?
 
Old 06-04-2009, 03:28 AM   #5
vasco2009
LQ Newbie
 
Registered: Feb 2009
Posts: 7

Original Poster
Rep: Reputation: 0
i see that.
Attached Thumbnails
Click image for larger version

Name:	iptraf.JPG
Views:	92
Size:	56.4 KB
ID:	760  
 
Old 06-05-2009, 07:02 AM   #6
janhe
Member
 
Registered: Jul 2007
Location: Belgium
Distribution: slackware64 14.2, slackware 13.1
Posts: 371

Rep: Reputation: 54
A few things you could try:
- toggle the promiscuous setting in iptraf
- check if the IP traffic arrives at your pc
the following command should list some IP packets:
Code:
tcpdump -c 1000 -i eth1
It captures the first 1000 packets that arrive at eth1

Edit: You do realise that those numbers that you see in your screenshot are mac addresses? I see one from a Cisco NIC, some from a D-Link NIC, and some of manufacturers I've never heard off

Last edited by janhe; 06-05-2009 at 07:05 AM.
 
Old 06-06-2009, 05:25 AM   #7
vasco2009
LQ Newbie
 
Registered: Feb 2009
Posts: 7

Original Poster
Rep: Reputation: 0
yes i know this is mac address, but i don't understand why iptraf don't "read" the packet. because it seems to work with tcpdump.

do you think it's because of a vlan ?

i put the promisc mode on in iptraf
 
Old 06-07-2009, 09:05 AM   #8
janhe
Member
 
Registered: Jul 2007
Location: Belgium
Distribution: slackware64 14.2, slackware 13.1
Posts: 371

Rep: Reputation: 54
I don't know the inner workings of iptraf.

You say the packets arrive on the network interface, so that isn't the problem. (AFAIK end devices don't know if they are in a Vlan or not, but I'm not certain)

Does iptraf filter any traffic (Filter...->IP...) ?
That is my last guess. Those non-IP packets probably really are non-IP packets, they all are 183 bytes.

Good luck.

Last edited by janhe; 06-07-2009 at 09:07 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
dlink 504t + snort(port mirroring) baztheallmighty Linux - Networking 1 09-07-2006 05:05 PM
Disk Mirroring via Network Drunkalot Linux - General 1 09-13-2005 08:29 PM
Network Login - mirroring users/passwords Kahless Linux - Software 2 07-13-2005 05:13 AM
any improved version of iptraf or any other utility like iptraf..? shahg_shahg Linux - Networking 1 03-07-2005 12:58 AM
iptraf and port 20? Timon79 Linux - Networking 4 01-12-2003 03:20 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:53 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration