LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 01-09-2007, 05:55 PM   #1
roopunix
Member
 
Registered: Feb 2004
Location: Kathmandu
Distribution: Redhat/fedora/Suse [Wanna Drive With Debian]
Posts: 208

Rep: Reputation: 30
Capture Network Statstics


I have a very strange question.I have a router installed By My ISP.That connects to my Remote branch office.Suddenly since two days My Network is getting hung.So i Discovered that once that Router is plugged in to the network then my whole network is down(I could not sleep the whole night).But just to be sure i wanted to be conformed if the flooding is from the router or from my remote branch.
But i don;t know the IPadress and the Netmask of the router.
So if there was a way to know that.

The folowwing is my topology
A dlink switch.The linux box Ethernet,the router's Etherenet is connected to it.In my linux i have installed an application that shows me who is uploading too much.So if i could know my Router's IPaddress and netmask i would know what is happening,
Is there any free utilities that can show me this one.Becuase My linux is in a different Net and router in a different Net.So if i know the router's net then i i will move my Linux also to the sme net.(Don't tell me to ask My ISP.My ISP is Useless.Most of the times they ask me about their assigned IP Address)
Than you and regards
 
Old 01-09-2007, 07:33 PM   #2
Brian1
LQ Guru
 
Registered: Jan 2003
Location: Seymour, Indiana
Distribution: Distribution: RHEL 5 with Pieces of this and that. Kernel 2.6.23.1, KDE 3.5.8 and KDE 4.0 beta, Plu
Posts: 5,700

Rep: Reputation: 65
If I understand this can you do a traceroute to say googles ip and see the IPs that are seen along the route. Only tools I know of that are simply like iptraf if set to view the linux ethernet port should show outside IPs that are coming and going.

Just to make sense of your setup. A router provided by your ISP. Then you have a cable going from the router to a dlink switch. Now from the Dlink switch you are connecting to the Linux box.

As far as the Linux IP is it a non-routable IP like 192.168.x.x or real world internet IP with a partial netmask seen directly from the outside world?

Now if it is non-routable IP then you can use a scan tool that can scan for ports or your IP. http://www.hackerwatch.org/probe/ or for just IP seen from the Internet http://www.whatismyip.com/

If the IP seen from the internet is it the same as the Linux box IP or maybe the lan side of the router IP.

Also what is the make and model of the router.

Brian
 
Old 01-09-2007, 07:36 PM   #3
chrisortiz
Member
 
Registered: Nov 2005
Distribution: Slackware, and of course the super delux uber knoppix universal live recovery cd
Posts: 429

Rep: Reputation: 30
your default gateway is your router. so type
Code:
route
look for an entry with the flag UG. The flags mean the interface is up and it is your gateway.

[EDIT]
if it was installed by your isp, i would port scan it to see what ports they have open.

nmap urgatewayip

to sniff the traffic on the link place a hub on the inside network of the router and hook up a linux box with ethereal, place your nic in promiscious mode. This should scan all traffic on the link without any interruption. Ethereal will give you source and desitnation address, which will allow you to find out where your attack is comming from, what type of attack.

Last edited by chrisortiz; 01-09-2007 at 07:50 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
capture SSID of wifi network powah Linux - Software 7 09-01-2005 07:14 PM
How to capture network packet jerrytw Programming 1 01-06-2005 10:28 AM
Capture IM traffic on the network shelby Linux - Security 1 08-10-2004 01:53 PM
Program to capture all Http requests in a Network leninkoduru Linux - Security 4 02-02-2004 02:00 AM
Network packet capture avaya Linux - Newbie 2 10-14-2002 09:37 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:33 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration