| Author |
Message |
greg_mitch
Joined: 03 May 2006 Posts: 5320
|
| Posted: Mon Sep 21, 2009 2:06 am Post subject: Network Traffic Monitor |
|
|
I would like to install some software that will log each IP on my network and its traffic both local and internet. Something that I could see in summary form is most helpful. Like data transfer per week/month per IP.
Anyone know of any good software? There are some things that my Dlink 825 can provide through the logs but nothing in a polished format.
Google is popping up a few but wanted to know if there was one program everyone else was using.
Thanks.
|
|
| Back to top |
|
 |
greg_mitch
Joined: 03 May 2006 Posts: 5320
|
| Posted: Mon Sep 21, 2009 1:43 pm Post subject: |
|
|
Turns out my network card doesnt support promiscous mode so I don't think I can do this from my laptop...anyone know what I am talking about....I don't really.
|
|
| Back to top |
|
 |
garyfritz
Joined: 08 Apr 2006 Posts: 12088 Location: Fort Collins, CO
|
| Posted: Mon Sep 21, 2009 1:58 pm Post subject: |
|
|
Promiscuous mode is used for packet sniffing. The card snags every packet that goes across the wire instead of only packets that are addressed to it. Then the CPU can examine and log it.
I'm no expert but I think it can only see traffic to/from nodes on your local subnet. Anything else will not be sent on your local wire.
http://www.wireshark.org is a popular sniffer / protocol analyzer. I've never used it but it's supposed to be good. http://www.ethereal.com is another big one.
|
|
| Back to top |
|
 |
ecrabb Forum Moderator
Joined: 13 Mar 2006 Posts: 15909 Location: Utah
TV/Projector: JVC RS40, Epson 5010
|
|
| Back to top |
|
 |
garyfritz
Joined: 08 Apr 2006 Posts: 12088 Location: Fort Collins, CO
|
| Posted: Mon Sep 21, 2009 2:28 pm Post subject: |
|
|
|
Steve, from a quick look at the SW site, it looks like the free tool is only for analyzing NetFlow traffic -- which appears to be a proprietary protocol for Cisco routers. If Greg has a network full of Cisco routers he might be able to use it, but if he's just trying to eavesdrop on his local traffic I don't think it's the right tool.
|
|
| Back to top |
|
 |
jkruger
Joined: 24 Oct 2007 Posts: 2435 Location: Carlsbad, CA
|
| Posted: Mon Sep 21, 2009 2:31 pm Post subject: |
|
|
|
I have wondered sometimes if my network is slow due to one of my "housemates" having a virus on her pc that is slowing it down. With this I could identify all the traffic on my network?
|
|
| Back to top |
|
 |
dturco
Joined: 06 Feb 2009 Posts: 3778 Location: Eastern Shore Maryland
TV/Projector: Runco DLP VX-3000i Marquee 9500 parts doner
|
| Posted: Mon Sep 21, 2009 2:41 pm Post subject: |
|
|
Who thought this up? Promiscuous mode is used for packet sniffing.
I just have this vision of a dog walking up and sniffing, getting promiscuous,and humping away
_________________ Firefly rules. Can't stop the signal.
http://www.hulu.com/firefly
|
|
| Back to top |
|
 |
akajester
Joined: 09 Jul 2008 Posts: 934 Location: Wisconsin
|
| Posted: Mon Sep 21, 2009 4:05 pm Post subject: |
|
|
Greg, what I've used is called ntop. I just set up a simple ubuntu linux box, it was a pentium 4 machine I had laying around, then installed ntop.
http://www.ntop.org/overview.html
All it requires is two nics or a monitor port on a switch and it'll gather every machine passing through it, and gives you protocal graphs, usage graphs, etc. It's amazing.
Very easy to install too;
https://help.ubuntu.com/community/Ntop
hope that helps,
|
|
| Back to top |
|
 |
greg_mitch
Joined: 03 May 2006 Posts: 5320
|
| Posted: Tue Sep 22, 2009 12:37 am Post subject: |
|
|
Thanks for the tips guys.
SC,
It came up when people posted they were blocking the Samsung Live Update site at their router so the live update wouldn't break their BR player. It got me thinking...how many other devices do I have connected or software I have running that is constantly chatting over the internet? I was more or less just curious...and I also caught "Andy's iPod" logged into my unsecured network the other day so I wanted to see what else was going on. I know, I know...it should be secured...I will get around to it...my N network is secure.
So many devices with an ethernet connection now.
|
|
| Back to top |
|
 |
ecrabb Forum Moderator
Joined: 13 Mar 2006 Posts: 15909 Location: Utah
TV/Projector: JVC RS40, Epson 5010
|
| Posted: Tue Sep 22, 2009 1:07 am Post subject: |
|
|
Dude... You have an open wifi router? Some evil conservative tea party attendee could park in front of your house in his pickup truck (complete with gun rack) and use your router to email death threats to President Obama... The Secret Service would then be knocking on YOUR door to check it out! What are you thinking?!?!!
SC
|
|
| Back to top |
|
 |
greg_mitch
Joined: 03 May 2006 Posts: 5320
|
| Posted: Tue Sep 22, 2009 1:41 am Post subject: |
|
|
|
Wifi squatting is a felony. I'm not worried about it. I am sure we could track MAC addresses right??
|
|
| Back to top |
|
 |
ecrabb Forum Moderator
Joined: 13 Mar 2006 Posts: 15909 Location: Utah
TV/Projector: JVC RS40, Epson 5010
|
| Posted: Tue Sep 22, 2009 2:06 am Post subject: |
|
|
I don't know about unauthorized WiFi use being a felony, Greg... That may be true in some states or locales, but not necessarily others.
Oh, and MAC addresses are easily spoofed.
SC
|
|
| Back to top |
|
 |
greg_mitch
Joined: 03 May 2006 Posts: 5320
|
| Posted: Tue Sep 22, 2009 3:46 am Post subject: |
|
|
Just google it...it is reported all the time. People stealing Starbucks wifi in the parking lot is illegal. I think third degree felony. Still a felony. You might have to show malicious intent. But I am sure I could scare a few neighbors to back off.
Not really my intent though...really I was just curious to see my entire usage over the course of a month. I always see that 5GB limit for wireless carriers and wonder how far over I really am.
|
|
| Back to top |
|
 |
WanMan
Joined: 19 Mar 2006 Posts: 10270
|
| Posted: Tue Sep 22, 2009 11:17 pm Post subject: |
|
|
I've used Solarwinds professionally, but never in a personal (at home) setting. Way overkill.
_________________ Trust no one. Absolutely no one. Advice of the board.
|
|
| Back to top |
|
 |
WanMan
Joined: 19 Mar 2006 Posts: 10270
|
| Posted: Tue Sep 22, 2009 11:19 pm Post subject: |
|
|
| ecrabb wrote: | Dude... You have an open wifi router? Some evil conservative tea party attendee could park in front of your house in his pickup truck (complete with gun rack) and use your router to email death threats to President Obama... The Secret Service would then be knocking on YOUR door to check it out! What are you thinking?!?!!
SC | It doesn't have to be open. It can be opened within minutes by teahackers.
_________________ Trust no one. Absolutely no one. Advice of the board.
|
|
| Back to top |
|
 |
WanMan
Joined: 19 Mar 2006 Posts: 10270
|
| Posted: Tue Sep 22, 2009 11:22 pm Post subject: |
|
|
I would just buying a 5 year old Cisco router and monitoring packets on the Ethernet interface would do the trick, but this would capture traffic crossing only on an Ethernet switch sitting behind the router.
akajester, you had all of your traffic passing through this computer, which was acting as a router?
_________________ Trust no one. Absolutely no one. Advice of the board.
|
|
| Back to top |
|
 |
akajester
Joined: 09 Jul 2008 Posts: 934 Location: Wisconsin
|
| Posted: Wed Sep 23, 2009 12:59 am Post subject: |
|
|
| WanMan wrote: | I would just buying a 5 year old Cisco router and monitoring packets on the Ethernet interface would do the trick, but this would capture traffic crossing only on an Ethernet switch sitting behind the router.
akajester, you had all of your traffic passing through this computer, which was acting as a router? |
I had the computer on a monitor port of our core switch, so the switch duplicated all traffic including internet bound to that port. Worked great. You could stick a hub in the middle too and do it that way.
|
|
| Back to top |
|
 |
bujj
Joined: 17 Nov 2009 Posts: 3
|
| Posted: Tue Nov 17, 2009 12:17 pm Post subject: |
|
|
|
hm... as for me i prefer to use ProteMac Meter
|
|
| Back to top |
|
 |
|
|