LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 11-16-2004, 10:21 AM   #1
MarkMcQ
LQ Newbie
 
Registered: Nov 2004
Location: Toronto
Posts: 2

Rep: Reputation: 0
Remote NIC monitoring with Ethereal


I have four network monitoring boxes, each with a passive ethernet port monitoring a different network. These networks cannot be merged.

Presently, I run a main monitoring station with KDE. This station accesses a monitor port in the following manner:

1) ssh to the remote monitor box.
2) run ethereal installed on the monitor box.

This generates a lot of spurious X traffic on the local network, and requires me to upgrade ethereal 4 times.

I would like to create a "shared" ethernet port on each monitor box to do the following:

1) Run ethereal on the main station
2) monitor the "shared" port on the remote box.

In this way, I can keep the monitor boxes lean and mean (ie. no XWindows required, no separate ethereal, etc), and focus any display changes and upgrades on the main monitor box.

Can this be done?

Thanks in advance...

Mark.
 
Old 11-16-2004, 04:04 PM   #2
bignerd
Member
 
Registered: Nov 2004
Distribution: FC1, Gentoo, Mdk 8.1, RH7-8-9, Knoppix, Zuarus rom 3.13
Posts: 98

Rep: Reputation: 15
if you want to keep things lean an mean then you do NOT want to run ethereal as your capture. Run tcpdump -w and dump to a file something like -r dumpfile.dump.

Tcpdump is low in over head and text based. Then when you want to interprit the output just use Ethereal on your local box (x-windows or MS Windows) by importing the remote dump file. You can set a cron job to archive dumps on the remote boxes hourly, daily or whatever floats your boat.

That's how I'd do it anyway.

-b

edit: sorry I didn't answer your question about watching all boxes at once. A suggestion would be to append all the live dumps to the same file. >> should work. And then monitor that file with ethereal. Not sure if ethereal will continually reload the file though.

Last edited by bignerd; 11-16-2004 at 04:07 PM.
 
Old 11-16-2004, 05:09 PM   #3
MarkMcQ
LQ Newbie
 
Registered: Nov 2004
Location: Toronto
Posts: 2

Original Poster
Rep: Reputation: 0
Thanks for the reply.

What I am looking for, though, is something that would allow me to capture from a port remotely, I think. In that way, I would not have to run either ethereal or tcpdump on the monitor boxes (PII 350's, so every CPU cycle is important).

I have thought of an approach similar to what you are suggesting, and it would add a historical functionality, but Ethereal does allow more interactive trace capabilities, and that is what my users require.

I found rpcap on Sourceforge, which purports to allow one host to capture from another host's port, but it seems to have been in alpha since October 2002. I don't really want to risk that...

I have investigated tunneling, but that seems to require an IP address on the passive port, and I want to keep the port truly passive (absolutely NO TX data).

Any ideas?

Thanks,

Mark.

Last edited by MarkMcQ; 11-16-2004 at 05:11 PM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Remote Server Monitoring vaworx Linux - General 3 08-22-2005 09:27 AM
Remote monitoring software fechin Linux - Software 1 08-02-2005 04:04 AM
Remote packet monitoring? dx0r515t Linux - Security 2 03-12-2005 04:33 PM
Remote video monitoring jbolt Linux - General 1 08-02-2004 08:25 PM
How to exclude the arp requests of the monitoring NIC Bassam General 1 02-10-2004 01:29 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 06:47 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration