Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: Re: [Ethereal-users] IP phones and 3Com 3300 switch

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Martin Shurbanov <shurbanm@xxxxxxxxxxxxxxxxxx>
Date: Thu, 29 Aug 2002 13:24:48 -0400 (EDT)
You cannot see all traffic by definition on a regular switch port.
you either need to set it to span , put your workstation on an uplink port 
or use dsniff's arpspoof utility.

HTH

On Thu, 29 Aug 2002, Guy Harris wrote:

> On Thu, Aug 29, 2002 at 10:27:01AM -0400, Shawn Schiebrel wrote:
> > is there anything that ethereal would do to put the switch port in a mode
> > that would see the traffic?
> 
> Not deliberately.  Ethereal just uses libpcap/WinPcap to capture
> packets; the standard versions of libpcap just put the network interface
> into promiscuous mode if asked to, they do not do anything to switches
> (they aren't even aware of switches), and the same is true of the
> WinPcap library and driver.
> 
> You would probably find that tcpdump/WinDump also see that traffic.
> 
> Perhaps there's something special about the switch port into which your
> workstation is plugged.
> _______________________________________________
> Ethereal-users mailing list
> Ethereal-users@xxxxxxxxxxxx
> http://www.ethereal.com/mailman/listinfo/ethereal-users
>