Professional Documents
Culture Documents
SHARKFEST '08
Foothill College
March 31 - April 2, 2008
Capture
2 and
Copper Injection
ports
WinPcap
Wireshark Aggregation
Capturing Traffic: Analyzer Placement
Considerations:
Wired vs. Wireless
Switched Network Issues
Half-Duplex vs. Full-Duplex
Duplex
Access
Point
Switch
Half-Duplex – Hubbing Out
Switch
Half-Duplex – Hubbing Out
Switch
Port Spanning
interface fastethernet 0/1
Switch(config)#interface
port monitor fastethernet 0/2
Switch(config-if)#port
port monitor fastethernet 0/5
Switch(config-if)#port
port span
0/2 0/5
Switch
0/1
Full-Duplex
Duplex Tap Options
Copper or Fiber
Aggregating
Aggregating or Non-Aggregating
Passive (no power) or Active
Regenerating Taps
Advanced Taps (packet insertion, filtering)
10/100 Slim Tap: Non-aggregating tap with
dual power supplies and two monitor ports
– datastream A and datastream B.
Requires separate aggregation.
Switch
Overview of the Onsite Process
Key Issues:
High Latency (Client, Server, Link)
Packet Loss (Upstream, Downstream)
Congestion (Network, Receiver)
Configuration Problems (Service Unavailable, Loops)
Redirections (Routing, Service)
Interdependencies (Third Parties)
Low throughput (Itty-Bitty
Bitty Stinkin’ Packets)
Negotiation Faults (Protocol or Application Layer)
Reports
Overview of traffic
Protocol distribution
Conversations
ICMP traffic
… etc.