[PLUG] Unknown activity on DSL
Derek Loree
derek at infotects.com
Thu Dec 5 20:17:38 UTC 2002
On Thu, 2002-12-05 at 11:45, Steve Bonds wrote:
> On 5 Dec 2002, Derek Loree derek-at-infotects.com |PDX Linux| wrote:
>
> > The box that runs SniffIt does not have any firewall rules running
> > while I do the sniffing. I really want to see those packets. Good
> > point about the hub, but I ran "known" traffic through it and was able
> > to see that.
>
> You might try a restart on the hub, or even try a different brand
> hub. I've seem some truly strange things with consumer-grade hubs and
> packet capture such as every-few packets go to all ports, but most
> don't. Only the uplink port goes to all other ports, etc.
Not that I want you to point fingers, but do you know what brands are
the worst and what ones are the best; as far as "hub-like" behavior
goes?
>
> This may not be possible if things have to keep running, but you might try
> connecting the modem directly to your sniffer PC via a crossover and see
> if the activity blinks continue. That would eliminate any possiblity of
> hub-related silliness.
This is a very good suggestion, I think I can get away with it if I stay
up really late, after all of my "users" have gone to bed.
>
> Another option would be to try a different sniffer just in case some wierd
> sniffer bug is involved.
Another good idea, have you had better results from one particular
sniffer?
Thanks for the ideas,
Derek Loree
More information about the PLUG
mailing list