Right and wrong.

The IS VLAN is its own broadcast domain and the HR VLAN is its own broadcast
domain.  By simply hooking up a sniffer to the HR VLAN, you would not see
any of the traffic that only transgresses the IS VLAN.  If someone from the
IS VLAN is going to a device on the HR VLAN, then you would be able to see
their traffic.

The Catch

If you have enable access to the switch, you can hook up a sniffer to a port
on the switch and make all broadcast traffic for either VLAN be seen by a
certain port.

Any questions?

Kelly D Griffin, CCNA, CCDA
Network Engineer
Kg2 Network Design
http://www.kg2.com


----- Original Message -----
From: "NetEng" <[EMAIL PROTECTED]>
Newsgroups: groupstudy.cisco
To: <[EMAIL PROTECTED]>
Sent: Wednesday, March 21, 2001 3:45 PM
Subject: Whew! Can you smell that VLan?


> We have had a pissing match lately and here's the details. One person
states
> that a VLan can not be sniffed because it is on a different subnet. The
> other person says it can becuase it's physically on the same switch. I
think
> you can to a point. Here's what I mean; let's say we have a 3524 with two
> Vlans, VLAN1 (we'll call it InfoSys), and VLAN2 (called HR). If I have a
> sniffer running on InfoSys, I should be able to sniff traffic on my subnet
> as well as traffic from HR to InfoSys (ie HR employee accessing mail
server
> on InfoSys), right? The only difference is that the source MAC address
would
> change. I should not be able to sniff traffic local to HR (ie an employee
> accessing accounting software) right? What's the rub?
>
>
>
>
> _________________________________
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
> ____________________________________________
> http://1cis.com
> Free E-mail Servers with unlimited mailboxes
> 1st Class Internet Solutions

____________________________________________
http://1cis.com
Free E-mail Servers with unlimited mailboxes
1st Class Internet Solutions

_________________________________
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

Reply via email to