Return to the CurtPalme.com main site CurtPalme.com Home Theater Forum
A forum with a sense of fun and community for Home Theater enthusiasts!
Products for Sale ] [ FAQ: Hooking it all up ] [ CRT Primer/FAQ ] [ Best/Worst CRT Projectors List ] [ Setup Tips & Manuals ] [ Advanced Procedures ] [ Newsletter ]
 
Blu-ray disc release list and must-have titles. Buy the latest and best Blu-ray titles to show off in your home theater!

 As this forum is rarely used anymore, we've locked it. Feel free to browse and read. Questions? Please reach out to us directly. Cheers! 

Network Traffic Monitor

 
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    CurtPalme.com Forum Index -> Home Theater PCs
Author Message
greg_mitch



Joined: 03 May 2006
Posts: 5320


Posted: Mon Sep 21, 2009 2:06 am    Post subject: Network Traffic Monitor

I would like to install some software that will log each IP on my network and its traffic both local and internet. Something that I could see in summary form is most helpful. Like data transfer per week/month per IP.

Anyone know of any good software? There are some things that my Dlink 825 can provide through the logs but nothing in a polished format.

Google is popping up a few but wanted to know if there was one program everyone else was using.

Thanks.
Back to top
greg_mitch



Joined: 03 May 2006
Posts: 5320


Posted: Mon Sep 21, 2009 1:43 pm    Post subject:

Turns out my network card doesnt support promiscous mode so I don't think I can do this from my laptop...anyone know what I am talking about....I don't really. Embarassed
Back to top
garyfritz



Joined: 08 Apr 2006
Posts: 12088
Location: Fort Collins, CO

Posted: Mon Sep 21, 2009 1:58 pm    Post subject:

Promiscuous mode is used for packet sniffing. The card snags every packet that goes across the wire instead of only packets that are addressed to it. Then the CPU can examine and log it.

I'm no expert but I think it can only see traffic to/from nodes on your local subnet. Anything else will not be sent on your local wire.

http://www.wireshark.org is a popular sniffer / protocol analyzer. I've never used it but it's supposed to be good. http://www.ethereal.com is another big one.
Back to top
ecrabb
Forum Moderator


Joined: 13 Mar 2006
Posts: 15909
Location: Utah

TV/Projector: JVC RS40, Epson 5010

Posted: Mon Sep 21, 2009 2:16 pm    Post subject:

OK, I have to ask, Greg.... Why do you want to monitor all traffic on your LAN and into/out of your WAN?

Oh, and Chris Perillo is always raving about SolarWinds stuff...

http://www.solarwinds.com/products/freetools/netflow_analyzer.aspx

SC
Back to top
View user's photo album (10 photos)
garyfritz



Joined: 08 Apr 2006
Posts: 12088
Location: Fort Collins, CO

Posted: Mon Sep 21, 2009 2:28 pm    Post subject:

Steve, from a quick look at the SW site, it looks like the free tool is only for analyzing NetFlow traffic -- which appears to be a proprietary protocol for Cisco routers. If Greg has a network full of Cisco routers he might be able to use it, but if he's just trying to eavesdrop on his local traffic I don't think it's the right tool.
Back to top
jkruger



Joined: 24 Oct 2007
Posts: 2435
Location: Carlsbad, CA

Posted: Mon Sep 21, 2009 2:31 pm    Post subject:

I have wondered sometimes if my network is slow due to one of my "housemates" having a virus on her pc that is slowing it down. With this I could identify all the traffic on my network?
Back to top
dturco



Joined: 06 Feb 2009
Posts: 3778
Location: Eastern Shore Maryland

TV/Projector: Runco DLP VX-3000i Marquee 9500 parts doner

Posted: Mon Sep 21, 2009 2:41 pm    Post subject:

Who thought this up? Promiscuous mode is used for packet sniffing.

I just have this vision of a dog walking up and sniffing, getting promiscuous,and humping away Laughing

_________________
Firefly rules. Can't stop the signal.

http://www.hulu.com/firefly
Back to top
akajester



Joined: 09 Jul 2008
Posts: 934
Location: Wisconsin

Posted: Mon Sep 21, 2009 4:05 pm    Post subject:

Greg, what I've used is called ntop. I just set up a simple ubuntu linux box, it was a pentium 4 machine I had laying around, then installed ntop.

http://www.ntop.org/overview.html

All it requires is two nics or a monitor port on a switch and it'll gather every machine passing through it, and gives you protocal graphs, usage graphs, etc. It's amazing.

Very easy to install too;
https://help.ubuntu.com/community/Ntop

hope that helps,
Back to top
greg_mitch



Joined: 03 May 2006
Posts: 5320


Posted: Tue Sep 22, 2009 12:37 am    Post subject:

Thanks for the tips guys.

SC,

It came up when people posted they were blocking the Samsung Live Update site at their router so the live update wouldn't break their BR player. It got me thinking...how many other devices do I have connected or software I have running that is constantly chatting over the internet? I was more or less just curious...and I also caught "Andy's iPod" logged into my unsecured network the other day so I wanted to see what else was going on. I know, I know...it should be secured...I will get around to it...my N network is secure.

So many devices with an ethernet connection now.
Back to top
ecrabb
Forum Moderator


Joined: 13 Mar 2006
Posts: 15909
Location: Utah

TV/Projector: JVC RS40, Epson 5010

Posted: Tue Sep 22, 2009 1:07 am    Post subject:

Dude... You have an open wifi router? Some evil conservative tea party attendee could park in front of your house in his pickup truck (complete with gun rack) and use your router to email death threats to President Obama... The Secret Service would then be knocking on YOUR door to check it out! What are you thinking?!?!!

Smile

SC
Back to top
View user's photo album (10 photos)
greg_mitch



Joined: 03 May 2006
Posts: 5320


Posted: Tue Sep 22, 2009 1:41 am    Post subject:

Wifi squatting is a felony. I'm not worried about it. I am sure we could track MAC addresses right??
Back to top
ecrabb
Forum Moderator


Joined: 13 Mar 2006
Posts: 15909
Location: Utah

TV/Projector: JVC RS40, Epson 5010

Posted: Tue Sep 22, 2009 2:06 am    Post subject:

I don't know about unauthorized WiFi use being a felony, Greg... That may be true in some states or locales, but not necessarily others.

Oh, and MAC addresses are easily spoofed.

SC
Back to top
View user's photo album (10 photos)
greg_mitch



Joined: 03 May 2006
Posts: 5320


Posted: Tue Sep 22, 2009 3:46 am    Post subject:

Just google it...it is reported all the time. People stealing Starbucks wifi in the parking lot is illegal. I think third degree felony. Still a felony. You might have to show malicious intent. But I am sure I could scare a few neighbors to back off.

Not really my intent though...really I was just curious to see my entire usage over the course of a month. I always see that 5GB limit for wireless carriers and wonder how far over I really am.
Back to top
WanMan



Joined: 19 Mar 2006
Posts: 10270


Posted: Tue Sep 22, 2009 11:17 pm    Post subject:

ecrabb wrote:
OK, I have to ask, Greg.... Why do you want to monitor all traffic on your LAN and into/out of your WAN?

Oh, and Chris Perillo is always raving about SolarWinds stuff...

http://www.solarwinds.com/products/freetools/netflow_analyzer.aspx

SC
I've used Solarwinds professionally, but never in a personal (at home) setting. Way overkill.
_________________
Trust no one. Absolutely no one. Advice of the board.
Back to top
WanMan



Joined: 19 Mar 2006
Posts: 10270


Posted: Tue Sep 22, 2009 11:19 pm    Post subject:

ecrabb wrote:
Dude... You have an open wifi router? Some evil conservative tea party attendee could park in front of your house in his pickup truck (complete with gun rack) and use your router to email death threats to President Obama... The Secret Service would then be knocking on YOUR door to check it out! What are you thinking?!?!!

Smile

SC
It doesn't have to be open. It can be opened within minutes by teahackers. Very Happy
_________________
Trust no one. Absolutely no one. Advice of the board.
Back to top
WanMan



Joined: 19 Mar 2006
Posts: 10270


Posted: Tue Sep 22, 2009 11:22 pm    Post subject:

I would just buying a 5 year old Cisco router and monitoring packets on the Ethernet interface would do the trick, but this would capture traffic crossing only on an Ethernet switch sitting behind the router.

akajester, you had all of your traffic passing through this computer, which was acting as a router?

_________________
Trust no one. Absolutely no one. Advice of the board.
Back to top
akajester



Joined: 09 Jul 2008
Posts: 934
Location: Wisconsin

Posted: Wed Sep 23, 2009 12:59 am    Post subject:

WanMan wrote:
I would just buying a 5 year old Cisco router and monitoring packets on the Ethernet interface would do the trick, but this would capture traffic crossing only on an Ethernet switch sitting behind the router.

akajester, you had all of your traffic passing through this computer, which was acting as a router?


I had the computer on a monitor port of our core switch, so the switch duplicated all traffic including internet bound to that port. Worked great. You could stick a hub in the middle too and do it that way.
Back to top
bujj



Joined: 17 Nov 2009
Posts: 3


Posted: Tue Nov 17, 2009 12:17 pm    Post subject:

hm... as for me i prefer to use ProteMac Meter
Back to top
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.    CurtPalme.com Forum Index -> Home Theater PCs All times are GMT
Page 1 of 1
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum