cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1056
Views
0
Helpful
2
Replies

packet sniffing a trunk link

carl_townshend
Spotlight
Spotlight

Hi all, If I set up a trunk with all my vlans on one port, if I use ethereal and plug into it, will I see all broadcasts etc for all vlans?

When using ethereal, am i right in saying it still works without an ip ?

2 Replies 2

ropethic
Level 4
Level 4

You will need to setup a SPAN session with the trunked port as the source port to a destination port where the sniffer will be plugged into.

When monitoring a trunk source port all active vlan traffic is monitored.

You dont need an IP in order capture data.

http://www.cisco.com/en/US/products/hw/switches/ps708/products_tech_note09186a008015c612.shtml

jedavis
Level 4
Level 4

Hi Carl,

I believe that is true - you see all the traffic on all the Vlans. However, I think that span may strip off the dot1q headers so you don't know what vlan any particular packet came from. Set up a span/port monitoring session and give it a try. You have nothing to lose.

Ethereal (AKA Wireshark) does not even need the IP protocol bound to the monitor NIC.

Review Cisco Networking products for a $25 gift card