Re: Bogon IPs traffic only seen by netflow, confined within a VLAN only



On 4/10/06, Nicolai van der Smagt <nicolai.vandersmagt@xxxxxxxx> wrote:
Stef,

Why don't you just span the entire VLAN to a machine capable of running
tcpdump, use tcpdump -e to find the hardware address of the station(s)
sending the traffic, and look up that address in the CAM table of your
switch? Would be quicker than spanning 1 port at a time..


Kr,
Nicolai van der Smagt

Thanks to all who answered - basically the suggestions revolved around
the same type of solution I assumed originally to be needed
(span/mirror/monitor ports, one at a time, to a probe machine -
whether done via a script on the switch, itself, or controlled
remotely). The above solution is different (saving tons of work), and
it is in fact something I have tried in the past, but never been able
to get to work properly [the entire traffic]. I am thankful for the
reminder, as I could give it another shot. This 4506 is fairly knew,
so hopefully things have improved since last time I have tried this
...

Thanks again to all for answers - part of the hope I had was that
someone could perhaps recognize the pattern, itself - but, if not, I
promise I will get back to this list with a follow-up on our findings.

Stef



Relevant Pages

  • Re: sniffing packets on a switch
    ... The "some" problems you are talking about are that since a switch has no ... broadcast traffic, not the traffic of other hosts. ... I have heard that TCPdump ... >Do you Yahoo!? ...
    (Security-Basics)
  • Re: Will 2 NICs solve this problem?
    ... My poor wording for a switch that only speaks 10BT. ... I guess there could be short bursts then of "capture effect" with ... the Sun grabbing the ether and not letting go. ... will run tcpdump over the specified interface, ...
    (comp.sys.sun.admin)
  • RE: Network monitoring tools
    ... Unfortunately the switch is out of our control, ... instead what I've done is used tcpdump to capture packets on ... I tried using ethereal to generate some statistics from the tcpdump ... Subject: Network monitoring tools ...
    (RedHat)
  • Re: Mac OS X NAT/related TCP issue?
    ... so I'd confirm that with some netstat statistics. ... I ran tcpdump) sees everything. ... The switch does indeed believe the link to be half-duplex? ... I've never seen anything negotiate full duplex to it). ...
    (comp.sys.mac.system)
  • RE: how to saturate 100Mbit
    ... > Also you can try to dump traffic with tcpdump and send it with ... > frame size at ... but I need very good hardware to make this. ... To unsubscribe, ...
    (freebsd-net)