PCBUILD Archives

Personal Computer Hardware discussion List

PCBUILD@LISTSERV.ICORS.ORG

Options: Use Forum View

Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
David Gillett <[log in to unmask]>
Reply To:
PCBUILD - PC Hardware discussion List <[log in to unmask]>
Date:
Wed, 13 May 1998 18:37:53 -0800
Content-Type:
text/plain
Parts/Attachments:
text/plain (38 lines)
On 13 May 98 at 9:20, Brian P. Clifford wrote:

> I want to build a machine for tracking the traffic on our network.  We
> have TCP/IP, NETbeui, AppleTalk, DecNet, probably others.  What type of
> machine do I need to use for this task.  Can you recommend any particular
> components?

  If your network uses a HUB, a station anywhere in the net[*] can
see all of the traffic, and all you need is software that "speaks"
the protocols you need.
  [*] BRIDGES and REPEATERS break the network into segments.  A
station on a broken segment won't see traffic, even if other parts of
the network are up....

  If your network uses SWITCHES (the one I'm responsible for at work
does), each station sees only traffic between itself and the switch.
To sniff a particular station's traffic, I need to insert a hub
between station and switch, and connect the sniffer to that hub.

  Obviously, it's going to be important to understand which case
applies to you.

> Do I need 2 network cards?

  Only if you need to sniff on multiple networks/subnetworks.
Generally, you'll plug the sniffer into whatever network you're
currently interested in.

> Is there any particular program you would recommend for sniffing
> the traffic?

  It's been several years since I bought one (early 1995), and in
fact I'm a bit interested in getting one now (but see above comment
about switched networks...).  I'll be interested in what people
recommend.

David G

ATOM RSS1 RSS2