LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 02-29-2016, 06:42 AM   #1
unclesamcrazy
Member
 
Registered: May 2013
Posts: 200

Rep: Reputation: 1
Use wireshark to see LAN's other systems website traffic


Hello Sir,

I have installed wireshark on my centos. I am able to open its UI.
There are more systems connected to same LAN whose IP range is same as mine i.e. 192.168.0.x

I want to see website list opened by other systems (not credentials, just websites what they are opening, nothing illegal), I have this monitoring task. I need to check if someone is downloading from torrents or someone is opening facebook and google plus all day or someone is listening on line music all day, this type of task I need to check.

Where should I go in wireshark menu to see these activities with their respective IPs. It would be fine if I would know IP and opened website name by it and nothing else (do not want to do any hacking or something)

Please help.

Thank You

Last edited by unclesamcrazy; 02-29-2016 at 06:44 AM.
 
Old 02-29-2016, 07:15 AM   #2
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,475

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
If your LAN uses a switch you won't be able to see the other traffic due to the way switches work.

If you want to sniff all traffic on your network you'll either need a switch with a monitoring port (effectively a switch port that DOES see all the traffic going through the switch) or you'll need to transparently have your sniffing box between your network switch and your edge router/firewall.
 
Old 02-29-2016, 07:46 AM   #3
unclesamcrazy
Member
 
Registered: May 2013
Posts: 200

Original Poster
Rep: Reputation: 1
We are using Router but I am not sure, there is Network switch or not.
Isn't it any solution to see this data in wireshark.

Proxy server is the last solution, I would like to use because it will take lots of time and number of permissions.
Wireshark looks easy to use and it has good UI just I am not able to see the data what I want to see.

Thanks
 
Old 03-01-2016, 07:09 AM   #4
btmiller
Senior Member
 
Registered: May 2004
Location: In the DC 'burbs
Distribution: Arch, Scientific Linux, Debian, Ubuntu
Posts: 4,290

Rep: Reputation: 378Reputation: 378Reputation: 378Reputation: 378
There's really no way to intercept all traffic from an unmanaged switch unless you do something seriously not nice such as exhausting its forwarding table so that it goes back to broadcasting all traffic on all ports (which will introduce serious lag and other problems into your network). As TenTenths said, most managed switches have some way to set up a monitoring port that all traffic can be mirrored to. If you have administrative access to your switch, you might want to look around in its configurationto see if you can find this option. If you have multiple PCs on the LAN, you probably have some sort of switch somehow.

The easiest thing honestly seems to put some sort of security gateway between the switch and the router; maybe just a Linux box that has a transparent bridge and running Wireshark. You can definitely use Wireshark for this - you just need to put your data collector someplace where it can see all traffic, e.g.:

Code:
<< Internet >>
    |
    |
  [ router ]
    |
    |
  [ Linux Wireshark collector ]
    |
    |
  [ switch ]
    / | \
<< workstations >>
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Wireshark is missing traffic? sree_ec Linux - Networking 2 09-27-2012 05:48 AM
wireshark traffic landorone1 Linux - Mobile 1 12-19-2011 01:36 PM
TCPDUMP -- how to monitor traffic between one machine in My LAN and one website. urhackking Linux - Security 8 12-16-2002 10:58 PM
TCPDUMP -- how to monitor traffic between one machine in My LAN and one website. urhackking Linux - Software 1 12-14-2002 03:05 PM
TCPDUMP -- how to monitor traffic between one machine in My LAN and one website. urhackking Linux - Networking 2 12-14-2002 02:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 05:25 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration