LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-15-2007, 11:09 PM   #1
LinuxNewbie999
Member
 
Registered: Oct 2006
Distribution: FreeBSD
Posts: 162

Rep: Reputation: 30
how to view all the packets in LAN connected to switch


How do I able to pickup all the packets in the LAN which is connected to a Switch? Is there any software that can sniff the packets from the LAN?
 
Old 09-15-2007, 11:50 PM   #2
farkus888
Member
 
Registered: Oct 2006
Distribution: usually use arch
Posts: 103

Rep: Reputation: 15
that would be very tricky. the problem is they way tcp/ip handles traffic you will only get traffic meant for your interface and broadcast traffic. the switch is the only device that would normally see all of that traffic. I personally am setting up something like this to monitor all the traffic that leaves my network. but with it being between a switch and my cable modem it will only be able to see traffic headed for the internet. traffic headed peer to peer on my network is going to be missed because they switch handles it and forwards it before it gets to the firewall. fine for my purpose of catch dubious traffic from malware and blocking traffic from dubious sites such as doubleclick from ever touching my network. I am using snort for scanning and pf for firewalling. more information about your exact goals might help us find a solution for you.
 
Old 09-16-2007, 12:09 AM   #3
Micro420
Senior Member
 
Registered: Aug 2003
Location: Berkeley, CA
Distribution: Mac OS X Leopard 10.6.2, Windows 2003 Server/Vista/7/XP/2000/NT/98, Ubuntux64, CentOS4.8/5.4
Posts: 2,986

Rep: Reputation: 45
They do make some types of hardware switches with a "mirror" port. You could plug your network sniffing cable to see what is going on, but not all hardware switches have this. Other than that, I have no idea if you can sniff switches without this mirror port.
 
Old 09-16-2007, 03:59 AM   #4
andrewdodsworth
Member
 
Registered: Oct 2003
Location: United Kingdom
Distribution: SuSE 10.0 - 11.4
Posts: 347

Rep: Reputation: 30
What I have is a linux machine between the switch and my modem/router to the internet. It's a router/firewall as well as a few other internal server bits. I can then run wireshark or ntop or other monitoring software on it and see what's going on and indeed control it.
 
Old 09-18-2007, 09:57 PM   #5
hottdogg
Member
 
Registered: Aug 2004
Distribution: opensuse ,debian/ubuntu
Posts: 222

Rep: Reputation: 30
based on my limited knowledge,
There are 2 kind of n/w sniffing.
1)passive sniffing
2)active sniffing

What you want is fall to the 2nd category, because of the way switch /hub-switch work.
Somehow you have to redirect the traffic in your switched lan to your computer, this is known as Man In The Middle(MITM) attack. I think it's related to arp poisoning/spoofing.
And then Your computer must be capable to do ip forwarding and something like that.

I had tried passive sniffing successfully on simple LAN that using old-hub sometimes ago. Tried it with ettercap and wireshark.
But for active sniffing ,currently I don't have the strong drive to do it.Need More hard work...maybe sometime later
But there are some tools you can use to explore sniffing switch lan. It's not that cutting edge method.
This is not exhausted list.
For win:
cain & abel
For lin:
ettercap
dsniff
thc parasite
wireshark( maybe? )

Oh...and try it in your own n/w! Trying this kind of stuff in office or public LAN might be illegal.

Let us know your result
 
Old 09-20-2007, 06:49 AM   #6
LinuxNewbie999
Member
 
Registered: Oct 2006
Distribution: FreeBSD
Posts: 162

Original Poster
Rep: Reputation: 30
Thanks. I'll try it on my LAN. Hopefully got good results.
 
Old 09-20-2007, 07:40 AM   #7
LinuxNewbie999
Member
 
Registered: Oct 2006
Distribution: FreeBSD
Posts: 162

Original Poster
Rep: Reputation: 30
I try to install atk but got a configure error.

configure: error:
*** GLIB 2.0.0 or better is required. The latest version of
*** GLIB is always available from ftp://ftp.gtk.org/. If GLIB is installed
*** but not in the same location as pkg-config add the location of the file
*** glib-2.0.pc to the environment variable PKG_CONFIG_PATH.

i had GLIB-2.12 installed, maybe the location is not correct. How do i add the location of the file glib-2.0.pc to the environment variable PKG_CONFIG_PATH ?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
switch connected to the linux board hangs up mishal4 Linux - Hardware 2 11-10-2005 04:09 AM
How can I use ethereal to capture packets from other computer on the same switch/hub? abefroman Linux - Security 8 05-12-2005 10:58 AM
What is the best way to view data captured in packets with Ethereal? abefroman Linux - Security 4 05-07-2005 01:30 PM
Internet connected - cant view pages. chris_bell Mandriva 4 12-07-2004 11:50 PM
set up DSL thru SWITCH - winXp connected to SWITCH too husz Linux - Newbie 5 04-22-2004 12:08 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 02:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration