LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-15-2013, 05:26 PM   #1
bgs@pt
LQ Newbie
 
Registered: Jul 2012
Posts: 9

Rep: Reputation: 0
Ethernet tap


Hi everyone,

I'm having an hard time figuring out why can't I capture the packets flowing between two devices, in both drections, using a self made ethernet tap, which looks just like this one: http://fernandomagro.com/wp-content/...2010/05/rx.jpg

Both end devices (say, A and B) are connected to a switch. But since the sniffer (a regular laptop) only has one ethernet port I can't perform the sniffing, like it is presented in most web sites (e.g. http://wiki.wireshark.org/CaptureSet..._a_network_tap)

So, in order to "solve" this issue, I just plugged the 2 (tap) connector ports to the ones on the switch and, finaly, 1 port from the switch to the sniffer. I thought the packets would be broadcasted but every time I plug the connectors to the switch the connection between A and B is interrupted.

My setup scenario looks like the picture in attachment.

Any ideias?
Attached Thumbnails
Click image for larger version

Name:	tap.png
Views:	16
Size:	3.7 KB
ID:	12724  
 
Old 06-15-2013, 07:47 PM   #2
baldy3105
Member
 
Registered: Jan 2003
Location: Cambridgeshire, UK
Distribution: Mint (Desktop), Debian (Server)
Posts: 891

Rep: Reputation: 184Reputation: 184
Without knowing the exact wiring of the "tap" its hard to say,but I suspect you've created a loop which spanning tree is not dealing with due to unidirectional links.

A proper tap has to multiplex the transmit and receive paths of a full duplex connection into the receive path on the sniffers connection. You can't do this simply by wiring. You need a proper tap, a mirror port, or you can get away with a hub if you have one. Bear in mind that a hub changes the network connectivity to half duplex, if you are diagnosing a problem it changes the conditions of the fault so may mask whatever issue you are looking for.
 
Old 06-15-2013, 07:56 PM   #3
bgs@pt
LQ Newbie
 
Registered: Jul 2012
Posts: 9

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by baldy3105 View Post
Without knowing the exact wiring of the "tap"
what you mean? if it is cooper or fiber? it is cooper cable.

Quote:
Originally Posted by baldy3105 View Post
A proper tap has to multiplex the transmit and receive paths of a full duplex connection into the receive path on the sniffers connection. You can't do this simply by wiring. You need a proper tap, a mirror port, or you can get away with a hub if you have one. Bear in mind that a hub changes the network connectivity to half duplex, if you are diagnosing a problem it changes the conditions of the fault so may mask whatever issue you are looking for.
The ideia is not to use port mirroring or a Hub, which I already did (both implementations). I want to sniff packets on both directions on a single link, using a tap, to the sniffer. My question is if that is possible or not.

Note that if my sniffer had 2 interfaces I could just plug those two tap connectors (TX and RX) there and see the traffic using a packet sniffer (e.g. Wireshark). But since I only have 1 interface on the sniffer, I'd like to know how to solve this (if possible).
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ethernet Bridging with a TAP-Device jubi4d Linux - Networking 1 01-28-2012 06:24 AM
Need help with injecting raw ethernet frames using TAP interface knonaka Programming 1 04-29-2010 02:31 AM
IP and ethernet tunnelling using TUN/TAP johnniealan Linux - Networking 2 05-16-2009 12:19 PM
passive ethernet tap kpachopoulos General 3 09-14-2005 08:07 AM
combining data streams from an ethernet tap robin.shepheard Linux - Networking 0 08-19-2005 06:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 06:28 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration