Ethereal-users: RE: [Ethereal-users] Capturing ATM traffic

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "Giles Scott" <gscott2@xxxxxxxxxxxxxxxxxx>
Date: Wed, 26 Sep 2001 18:32:23 +0100
Title: RE: [Ethereal-users] Capturing ATM traffic

Hi

For Optical Traffic;
We used to use optical spiltters which would - split the light so an analyser could see all the traffic between two stations. They were quite expensive I think around $1000 USD. Sorry can't remember the manufacturer.

You would need two ATM cards in the PC. With TX from one source into RX on the first card, same on the other ATM card.

Certainly with Bay Networks - Centillion switches it was not possible to span/mirror ATM ports.


For Serial traffic ;
I guess the same thing can be done just a little more complex, I have done it in the past with RS232, not sure about X21 or V35 thou sounds far more complicated :-(

Giles Scott
Alteon WebSystems
CNBU Nortel Networks


-----Original Message-----
From: Allan Silverstein [mailto:allan@xxxxxxxx]
Sent: Wednesday, September 26, 2001 9:05 AM
To: tom greaser; Raghu Arni
Cc: ethereal-users
Subject: RE: [Ethereal-users] Capturing ATM traffic


You can sniff the scenario I mentioned by putting a sniffer "in-line"
between the Cisco Router ATM port and the ATM switch (using Internet
Advisor, Adtech,etc)

al silverstein

-----Original Message-----
From: ethereal-users-admin@xxxxxxxxxxxx
[mailto:ethereal-users-admin@xxxxxxxxxxxx]On Behalf Of tom greaser
Sent: Wednesday, September 26, 2001 8:46 AM
To: Raghu Arni
Cc: ethereal-users@xxxxxxxxxxxx
Subject: Re: [Ethereal-users] Capturing ATM traffic


If any one knows better please tell me im wrong...

If you have a physical link between just the two devices there is no way
(take that with a grain of salt i will explane later) fo you to sniff
that wire.  What you need to do is use your debug tools in your cisco
ios.  This will show you what traffic it sees and what its doing ...



The grain of salt part.. If you have these devices connected between via
a switch you can use the span command to see the traffic...

Since we are talking about traffic I will go off the subject just a
little.  I found a GREAT tool that spoofs the mac address so switch
traffic will be push the traffic to my linux box and my linux box
forwards that to the real destination..

these replace the need for admins to have to trace down what switch port
a user is in and use the span command.

http://www.monkey.org/~dugsong/dsniff/

My point is that even though ethereal is a SUPER ... GREAT tool.. That
if you use other great gnu tools with it you just about do anything you
want...


On Tue, 2001-09-25 at 16:34, Raghu Arni wrote:
> I actually have a similar question..I have two cisco routers connected
back
> to back via a serial link with FR. This might seem like a silly question
(My
> WAN knowlege is poor) but is there a way I can somehow sniff packets on
that
> link..?? Just curious..
>
> thx,
> Arni
>
>
> > How would I go about using Ethereal to capture ATM traffic.  For example
> if
> > I had a Cisco router with an ATM interface connected to an ATM switch
and
> I
> > wanted to see the traffic between the two.  If I were using a Network
> > General Sniffer of HP's Internet Advisor, I could put their sniffer
> > "in-line" beween the Router port and ATM switch port and capture
traffic.
> > How would I go about doing that with Ethereal.  If this is possible, I
> know
> > I would need an ATM NIC card (dual port???).  Where would I go from
> there??
> > Special drivers, etc, etc????
> >
> > Thanks
> > al silverstein
> >
> >
> > _______________________________________________
> > Ethereal-users mailing list
> > Ethereal-users@xxxxxxxxxxxx
> > http://www.ethereal.com/mailman/listinfo/ethereal-users
> >
>
>
> _______________________________________________
> Ethereal-users mailing list
> Ethereal-users@xxxxxxxxxxxx
> http://www.ethereal.com/mailman/listinfo/ethereal-users
--
Tom  Greaser

Ethereal
Sniffing the glue that holds the Internet together

Packets are no harder to forge than business cards.

_______________________________________________
Ethereal-users mailing list
Ethereal-users@xxxxxxxxxxxx
http://www.ethereal.com/mailman/listinfo/ethereal-users


_______________________________________________
Ethereal-users mailing list
Ethereal-users@xxxxxxxxxxxx
http://www.ethereal.com/mailman/listinfo/ethereal-users