LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-13-2011, 05:46 AM   #1
reeaver
LQ Newbie
 
Registered: Apr 2005
Distribution: Slackware
Posts: 8

Rep: Reputation: 0
Traffic monitoring and port mirroring


Hi,

I'm looking for some solution that helps me with traffic monitoring in some small network.

I need to log all visited sites and connections made by network users.
Currently in this network there is some simple router but it doesn't allow to log such data. I'm not able to change this router, it has to stay.

This router is connected to some smart switch which has a mirroring port feature.
I was thinking about use this feature and forward copy of all thaffic that flows to current router to some linux machine which will be able to analyse traffic.

But how to analyse traffic on such machine, what should I use?
Or maybe there is some better solution?

Thanks for all suggestions
 
Old 12-13-2011, 07:15 AM   #2
kbp
Senior Member
 
Registered: Aug 2009
Posts: 3,790

Rep: Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653
A proxy might be a better option as it already inspects the traffic and will do reporting
 
Old 12-13-2011, 07:29 AM   #3
reeaver
LQ Newbie
 
Registered: Apr 2005
Distribution: Slackware
Posts: 8

Original Poster
Rep: Reputation: 0
Ok but this will solve only a part of problem.
What about logging other traffic?
 
Old 12-13-2011, 07:39 AM   #4
kbp
Senior Member
 
Registered: Aug 2009
Posts: 3,790

Rep: Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653Reputation: 653
If this is for IDS you could probably start with snort.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to use VPN tunnel for all traffic except SMTP (port 25) traffic? maven12 Linux - Networking 2 11-09-2010 06:00 AM
monitoring traffic on specific port lildee Programming 2 10-03-2009 06:03 AM
[HELP] redirect traffic to spesific port based on Traffic Content using iptables summersgone Linux - Server 2 06-22-2009 11:26 AM
network monitoring with iptraf and port mirroring vasco2009 Linux - Networking 7 06-07-2009 09:05 AM
SNMP MRTG RRDTOOL Configu of CPU memory Disk Port data traffic doc traffic manish_2479 Linux - Networking 1 06-19-2007 07:08 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 11:38 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration