LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 04-04-2011, 09:06 PM   #1
emrysm
LQ Newbie
 
Registered: Jun 2009
Posts: 9

Rep: Reputation: 1
Ubuntu 10.10 as a dumb hub for network monitoring


Hello all,

I am currently stationed overseas in Japan, and I am happy to say that I have a 100 Mbit fiber line from my service provider... I am not so happy to say that they force me to use their "CTU", which is basically a Japanese router, which limits me from receiving external connections (such as would be required to host FTP, or administer my home machines via SSH or VNC). I have tried many methods of bypassing this piece of equipment, but so far none have worked (router setup for PPPoE, DHCP, Static IP, so on). I don't think the Japanese would mind me bypassing this device, as it's really there to 'protect' me, but there's such a language barrier that I can't figure out how to tell them what I want to do.

In order to troubleshoot the problem, I would like to setup a spare computer as a hub, dumbly (Is that a word? It is for this circumstance...) passing data from one device to the other, and allowing me to watch what is being passed via Wireshark.

I am pretty linux savvy, but I'm completely useless with iptables, and I was hoping someone might be able to help me out with this setup.

Here is the final product I want:

After connecting eth0 to the fiber modem and eth1 to the CTU, I want the computer to duplicate eth0's distant end MAC to eth1 and vice versa (to simulate the computer not being on the network at all), then I just want the computer to pass any data coming in on eth0 to eth1, and any data coming in on eth1 to eth0. Finally, I need to be able to read the throughput with Wireshark, but I really think that will be very simple if I can get the rest of the setup complete.

One piece of info - there is no dhcp on this link of the network, and I have no way of knowing the MAC addresses of either end before connecting them.

As an added bonus, once I've captured the handshake between the CTU and modem, if someone knows how to retransmit those packets on demand (i.e. to replace the CTU with my computer), I would be quite happy to hear about it.

Can anyone help?

~Emrys
 
Old 04-05-2011, 09:53 AM   #2
emrysm
LQ Newbie
 
Registered: Jun 2009
Posts: 9

Original Poster
Rep: Reputation: 1
After many hours banging my head on the keyboard, I came to an incredibly low tech solution to trick my little magic box into telling me its secrets.

1) Run Backtrack 4r2 on any computer with a network connection.
2) Run Wireshark in promiscuous mode, cable connected to NIC, but not suspect device.
3) While suspect device is operating normally, swap its cable for the one with Wireshark running.


It's not pretty, but it got me details... including that the CTU uses IPv6 and that opens a whole new can of worms.

I'd still love to hear a better solution if anyone finds one.

~Emrys
 
Old 04-05-2011, 04:51 PM   #3
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,978

Rep: Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623Reputation: 3623
Any system can run wireshark. Why not simply use it on the original system?
 
Old 04-06-2011, 12:35 AM   #4
emrysm
LQ Newbie
 
Registered: Jun 2009
Posts: 9

Original Poster
Rep: Reputation: 1
Quote:
Originally Posted by jefro View Post
Any system can run wireshark. Why not simply use it on the original system?
Since Backtrack already has all the tools I need and it runs as a live cd, I find it to be the easiest method for this type of network snooping. If you must know, the "original system" on that computer was BrazilFW, a text only router software I was trying to use to replace the CTU.

~Emrys
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
network monitoring:unable to launch nagios network monitoring system oladapo1980 Linux - Newbie 0 07-21-2009 01:45 PM
LXer: Monitoring Network Latency With Smokeping (Ubuntu 9.04) LXer Syndicated Linux News 0 07-16-2009 08:00 AM
LXer: Network Management And Monitoring With Hyperic HQ On Ubuntu 7.04 LXer Syndicated Linux News 0 08-28-2007 02:30 PM
Network/Hub conundrum spage0506 MEPIS 15 06-24-2005 09:51 AM
Remotely Monitoring a Hub EnigmaX Linux - Networking 1 05-26-2004 02:40 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:08 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration