[PLUG] Unknown activity on DSL

Derek Loree derek at infotects.com
Thu Dec 5 20:17:38 UTC 2002


On Thu, 2002-12-05 at 11:45, Steve Bonds wrote:
> On 5 Dec 2002, Derek Loree derek-at-infotects.com |PDX Linux| wrote:
> 
> > The box that runs SniffIt does not have any firewall rules running
> > while I do the sniffing.  I really want to see those packets.  Good
> > point about the hub, but I ran "known" traffic through it and was able
> > to see that.
> 
> You might try a restart on the hub, or even try a different brand
> hub.  I've seem some truly strange things with consumer-grade hubs and
> packet capture such as every-few packets go to all ports, but most
> don't.  Only the uplink port goes to all other ports, etc.

Not that I want you to point fingers, but do you know what brands are
the worst and what ones are the best; as far as "hub-like" behavior
goes?
> 
> This may not be possible if things have to keep running, but you might try
> connecting the modem directly to your sniffer PC via a crossover and see
> if the activity blinks continue.  That would eliminate any possiblity of
> hub-related silliness.

This is a very good suggestion, I think I can get away with it if I stay
up really late, after all of my "users" have gone to bed.
> 
> Another option would be to try a different sniffer just in case some wierd
> sniffer bug is involved.

Another good idea, have you had better results from one particular
sniffer?

Thanks for the ideas,

Derek Loree






More information about the PLUG mailing list