LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-04-2014, 03:14 PM   #1
turnbui
Member
 
Registered: Jul 2005
Location: UK
Posts: 101

Rep: Reputation: 15
My domestic phone - does it carry traffic for other computers.


I would like to monitor the traffic between my router/modem and my ISP. However, I am led to believe that traffic other than what is meant for my network may be sent and thrown away by my router/modem. Is this true? If so I can appreciate the security implications and thus not enable the ISP / router/modem monitoring. If this is not true then is it possible to monitor this traffic? If so how can this be accomplished?
thanks,
ian t.
 
Old 05-04-2014, 04:02 PM   #2
psycroptic
Member
 
Registered: Aug 2011
Location: USA
Distribution: ArchLinux - 3.0 kernel
Posts: 349

Rep: Reputation: Disabled
depending on your ISP, the WAN side of your router/modem may be constantly bombarded by ARP packets from their head-end, as well as occasional DHCP messages. it's all normal traffic, necessary for operation of the ISPs network. it would be possible to monitor this traffic if you have the requisite tools available on the router; though i'm not sure how interesting the results would be. and no, you typically cannot see other subscribers traffic.
 
Old 05-04-2014, 04:48 PM   #3
turnbui
Member
 
Registered: Jul 2005
Location: UK
Posts: 101

Original Poster
Rep: Reputation: 15
Thank you psycroptic.
"Tools on the router." Can you give the name of these tools?
cheers
ian t.
 
Old 05-04-2014, 04:55 PM   #4
psycroptic
Member
 
Registered: Aug 2011
Location: USA
Distribution: ArchLinux - 3.0 kernel
Posts: 349

Rep: Reputation: Disabled
Quote:
Originally Posted by turnbui View Post
Thank you psycroptic.
"Tools on the router." Can you give the name of these tools?
cheers
ian t.

sure; tcpdump, and its many associated front-ends (wireshark, tshark, etc.) is a packet trace utility. ran on the WAN interface of the router, it prints out info/payload for every packet that hits it.

i will say, if you do not have command-line access to the router, then it will be virtually impossible to run this (or any other utility) from its GUI config screens. though custom firmwares may. if this is one of those "combo" units rented out by ISPs, then you're hosed.
 
Old 05-04-2014, 06:20 PM   #5
turnbui
Member
 
Registered: Jul 2005
Location: UK
Posts: 101

Original Poster
Rep: Reputation: 15
Thanks for your info. I use wireshark on my NIC but it only shows the traffic on the local side, even with promiscuous mode set. I was hoping to see the other side of the modem/router.
ian t.
 
Old 05-04-2014, 10:14 PM   #6
psycroptic
Member
 
Registered: Aug 2011
Location: USA
Distribution: ArchLinux - 3.0 kernel
Posts: 349

Rep: Reputation: Disabled
Quote:
Originally Posted by turnbui View Post
Thanks for your info. I use wireshark on my NIC but it only shows the traffic on the local side, even with promiscuous mode set. I was hoping to see the other side of the modem/router.
ian t.
right, you would have to run wireshark ON the router directly, not on your machine.
 
Old 05-05-2014, 09:59 PM   #7
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,976

Rep: Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623
Depending on your system, you may or may not easily be able to actually monitor the wan. In some cases you can put your modem in bridged mode and authenticate via the computer.
In some cases you can nat the wan or dmz it to a computer.

But, yes, in most tcp/ip type situations where there is an IP address at the modem, there is also (could be) a lot of traffic. It may depend also on how your isp has devices configured and who is out trying to access your network. Millions of crooks have automated systems trying to attack any ip out there.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: The FBI Might Do More Domestic Surveillance than the NSA LXer Syndicated Linux News 0 11-26-2013 12:41 PM
How to block traffic initiated from computers in the DMZ? Winanjaya Linux - Security 3 04-03-2009 10:52 AM
recommendation needed for domestic security system keratos Linux - General 11 08-23-2008 11:39 AM
Filter traffic between computers same subnet matters Slackware 9 10-19-2007 02:42 AM
LXer: Gloomy prospects for domestic Linux industry LXer Syndicated Linux News 0 06-18-2006 05:33 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:10 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration