Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Ethereal-users: [Ethereal-users] Re: IP phones and 3Com 3300 switch

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: "Cluff, Jared B" <jared.b.cluff@xxxxxx>
Date: Thu, 29 Aug 2002 12:53:44 -0500
I don't believe that network monitor in the win2k pro/server listens in
permiscious mode, where as ethereal does.  The Network Monitor client
installed through MS SMS 1.2/2.0 however does listen in permiscious mode.
This is mostlikely your problem.  Also, switches by nature will not allow
you to sniff any traffic but what is on each specific port, so you usually
have to replicate the desired ports traffic to your sniffers port, but from
what I have gathered below, that isnt the case since ethereal seems to work
fine.

Vapor


----------------------------------------------

this is a very strange occurance.

I have 15 IP phones in my IT shop.. and all are connected via a 3com =
3300 switch matrix ( 4 actual switches matrixed together )
workstations ( including mine ) are also connected to the same switch =
matrix=20

when I use ethereal from my workstation, I can see the IP phones talk to =
the IP cards in the phone system... not a broadcast or multicast, but a =
real IP address talking to another real IP address... say 10.10.2.25 =
talking to 10.10.3.65. =20

No broadcast addresses at all involved. ( of course.. I see broadcasts =
as well with ethereal )

But if I fire up Network Monitor in win2k.. I don't see that traffic at =
all.. just the broadcasts and a few multicasts.. ( Like I am supposed to =
)

just wondering if anyone has ever seen anything like this....  is there =
anything that ethereal would do to put the switch port in a mode that =
would see the traffic?

Shawn Schiebrel , Systems Engineer
American Health Holding Inc.
614-818-3222 x1111

Jared Cluff
EDN Team - XO
615-777-1511 - Desk