-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Not to ask the obvious, but is this running in a switched
environment?
If so, you are seeing the traffic you should.
john
> -----Original Message-----
> From: Jason Brown [mailto:[EMAIL PROTECTED]]
> Sent: Friday, June 15, 2001 02:33 PM
> To: [EMAIL PROTECTED]
> Subject: Network Sniffers
>
>
>
> Hello All,
>
> I am trying to set up a sniffer so I can see what the users
> are doing on the
> Internet and see if they are abusing the service.
>
> To date I've install Ethereal and Ksnuffle but neither are
> working as they
> should.
>
> I can sniff traffic to and from the machine running the
> software, but the
> rest of the network traffic is not visible.
>
> According to all the documentation I found, the network cards
> are put into
> promiscuous mode automatically by the software. From what I
> can see, it's
> almost as if the cards are not.
>
> I've installed the software on RedHat 6.2 and 7.1 and used 2
> different types
> of NICs on 2 different machines, and one is a 3Com 590.
> Anybody know why I
> can't see everything???
>
> What I want to do is generate a graph that will tell me how much
> NNTP traffic in being pulled down. I know they are pulling down
> VCD files and I
> am 99% sure this is causing the slow response, but I'd like
> to have proof
> before I point fingers. Ksnuffle looks like it will work,
> but if someone
> else has another solution, please let me know.
>
> Thanks,
>
> Jason
>
> _______________________________________________
> Firewalls mailing list
> [EMAIL PROTECTED]
> http://lists.gnac.net/mailman/listinfo/firewalls
-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>
iQA/AwUBOypiotwfv0dRtjgLEQLfNQCeLRJGJ7y5hE2gwlaBxyilbMWMZH8AoLUR
SQd8QQLxxr1GaaXSqyqzOf//
=/43R
-----END PGP SIGNATURE-----
_______________________________________________
Firewalls mailing list
[EMAIL PROTECTED]
http://lists.gnac.net/mailman/listinfo/firewalls