Re: Dual-Homed/Triple-Subnet Bridge Challenge
Grant Taylor <[email protected]> Tue, 12 Feb 2008 13:52:05 -0600
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Organization | Riverview Technologies Inc. |
| Message-ID | <[email protected]> |
On 02/12/08 13:14, Vincent Callanan wrote: > This is fantastic assistance Grant. I'm glad that I was able to help. > I am chomping at the bit to get this up and running when I get back > on-site. I will report back when job is complete. *nod* Please do respond with a details post so that someone else like your self will hopefully find the response in the archives useful. > Just a by-the-way on this promiscuous mode business... > > I did in fact understand that modern switches (unlike old hubs) > monitor MAC activity and learn where source and destination ports > reside. However, I assumed that if a NIC is placed in promiscuous > mode, then this fact will somehow be communicated to the switch, > perhaps in some status bit in packet headers, and the switch will > then send all traffic to the NIC port. Obviously, from what you say, > this assumption is incorrect and I need have no concerns about my > server getting overloaded with extraneous traffic. About the only thing that the client computer can to to effect what is or is not sent to it (aside from doing some very nasty things with ARP) is to enable Spanning Tree Protocol and mis-configure it and or allow loops in the network. If you want to have a discussion about STP, just say the word. > But that leads me to ask the question: How do Linux network sniffing > utilities (which also use promiscuous mode) manage to pick up all > traffic? In short, they do not. The Linux (or what ever) networking sniffing utilities only see the traffic that comes to the NIC its self. That is why if you want to sniff a switched network you either need to put a Hub in-line or use a SPAN / Mirror port on a switch. This way, all the traffic makes it to the Linux (or what ever) system's NIC in promiscuous mode. Remember that switches and bridges will (by default) only send traffic to all ports if they do not know where the destination MAC is. Thus if they do know where the destination MAC is, they will send it only to the destination MAC, *NOT* all ports. Grant. . . . ------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2008. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/