|
Question : Ethereal / Wireshark network Sniff
|
|
This week I detect something wrong with my network. My network contain only 20 PC....I use etheral / wireshark to sniff the flow/stream in the network in order to detect for any errors. But I can't find any setting to sniff my whole local LAN. Can ethereal / wireshark can do that?
|
Answer : Ethereal / Wireshark network Sniff
|
|
It can only capture what it sees - this means if you're using it on a switch stub, you're not going to see much beyond broadcasts and locally originated or destined traffic. To see all traffic, you'd need a (managed) switch that supports mirroring of all traffic to a specific port, or to simply use a hub (not the best option, I know), or deploy the sniffer on a host through which the traffic to be monitored flows (ie you can run it on your firewall if you want to sniff internet traffic - not so helpful for LAN-to-LAN traffic though).
Cheers, -Jon
|
|
|
|