资源描述:
《怎样用sniffer监听交换机数据包(how to monitor switch packets with sniffer)》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、怎样用Sniffer监听交换机数据包(HowtomonitorswitchpacketswithSniffer)HowtomonitorgatewaypacketswithSnifferThe2009-09-17InanEthernetenvironment,communicationbetweentwoworkstationsisnotinterceptionbyathirdparty.Insomecases,wemightneedtodosuchalistening,suchasprotocolanalysis,trafficanalysis,intrusiondetec
2、tion.Forthispurpose,wecansettheSPANoftheCiscoswitch(SwitchedPortAnalyzerswitchingPortAnalyzer),ortheearly"Portmirroring"and"monitoringPort"feature.Thelisteningobjectcanbeoneormoreswitchports,ortheentireVLAN.Iftheport("sourceport")ortheport("targetport")tolistenonisonthesameswitch,wejustneed
3、toconfiguretheSPAN;Ifyouarenotonthesameswitch,youneedtoconfigureRSPAN(RemoteSPAN).DifferentswitcheshavedifferentrestrictionsonSPAN,suchasthesourceportsandtargetportsinthe2900XLswitchesmustbeinthesameVLAN,someswitchesdonotsupportRSPAN,andsoon,seethedevicedocumentation.WhenconfiguringSPAN,wen
4、eedtoprovidetheparametersthataresourceorVLANandtargetports.4000/6000CatOSswitches:Setspan6/176/19//span:thesourceportis6/17andthetargetportis6/192950/3550/4000ios/6000iosswitch:Monitorsession1local//SPANThemonitorsession1sourceinterface(sourceinterface)iseitherthesameoraVLANMonitorsession1d
5、estinationinterface(destinationinterface2900/3500xlexchange:Interface(interface):thernet0/19//targetportPortmonitor:the1900switch:(orusethemenu[M]Monitoring)Monitor-portmonitored0/17//sourceports(port0/17and0/18)Monitor-portmonitored0/18Monitor-portport0/19//targetportMonitor-port//startmon
6、itoringWhenconfiguringRSPAN,wefirstdefineaVLANtypethatisRSPAN.OnordinaryVLANifthesourcehostandthetargethostareonthesameswitch,theydon'tneedtopasstheTRUNKunicastcommunicationbetweentootherswitches,RSPANVLANneedsontheTRUNKforwardsuchcommunication,toensurethatmonitoringmachinetolistento.Onthes
7、ourceswitch,youneedtosetthelisteningportorVLANtoforwardtraffictotheRSPANVLAN(ifyouarerunninganIOSswitch,youneedtosetupanotherportasareflectionport);Onthetargetswitch,youneedtosetthemessageinRSPANVLANtothetargetportoftheconnectionmonitorhost.IOSswitches,s