Question : Ethereal / Wireshark network Sniff

This week I detect something wrong with my network. My network contain only 20 PC....I use etheral / wireshark to sniff the flow/stream in the network in order to detect for any errors. But I can't find any setting to sniff my whole local LAN. Can ethereal / wireshark can do that?

Answer : Ethereal / Wireshark network Sniff

It can only capture what it sees - this means if you're using it on a switch stub, you're not going to see much beyond broadcasts and locally originated or destined traffic.  To see all traffic, you'd need a (managed) switch that supports mirroring of all traffic to a specific port, or to simply use a hub (not the best option, I know), or deploy the sniffer on a host through which the traffic to be monitored flows (ie you can run it on your firewall if you want to sniff internet traffic - not so helpful for LAN-to-LAN traffic though).

Cheers,
-Jon
Random Solutions  
 
programming4us programming4us