Ethereal-users: [Ethereal-users] Ethereal/Packet Sniffing Problems

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "Kyle F." <uhnd@xxxxxxxxxxxx>
Date: Thu, 13 May 2004 17:40:18 -0700
I'm having some problems with Ethereal and other packet sniffers in general.  Here's my situation...
 
Home network, behind a Linksys 5 port 10/100 hub, consisting of Redhat machine, a Fedora machine, and a WinXP machine.  I've run multiple packet sniffers from each (Ethereal, tcpdump, Snort), and cannot detect network activity other than broadcasts, or traffic directed at the machine in question.  I read over your FAQ and it looks like this is a common problem.  I emailed Linksys, and they told me the hub I have should behave as a hub and not as a switch.  They said it's just pass through.  I made sure that the machines were all operating at the same speed (100), as the FAQ specified -- just in case.  So far, none of this has worked.
 
I use cable modem, so I tried to plug my machine directly into the modem to try and sniff network traffic in the neighborhood area.  Same problem.  All I see are lots and lots of ARP broadcasts.  This makes me think that either I'm doing something wrong with these programs, or my OS's or network cards do not go into promiscuous mode.
 
The two cards I'm using are the NETGEAR FA310TX Fast Ethernet PCI Adapter, and 3Com 3C920 Fast Ethernet.  Are there any known issues with these cards?  Any help would be appreciated.  I've been struggling with this for awhile.
 
Thanks ahead.