Re: Dual-Homed/Triple-Subnet Bridge Challenge

Grant Taylor <[email protected]> Tue, 12 Feb 2008 13:52:05 -0600
Newsgroups gmane.linux.network.bridge.ebtables.user
Organization Riverview Technologies Inc.
Message-ID <[email protected]>
On 02/12/08 13:14, Vincent Callanan wrote:
> This is fantastic assistance Grant.

I'm glad that I was able to help.

> I am chomping at the bit to get this up and running when I get back 
> on-site.  I will report back when job is complete.

*nod*

Please do respond with a details post so that someone else like your 
self will hopefully find the response in the archives useful.

> Just a by-the-way on this promiscuous mode business...
> 
> I did in fact understand that modern switches (unlike old hubs) 
> monitor MAC activity and learn where source and destination ports 
> reside.  However, I assumed that if a NIC is placed in promiscuous 
> mode, then this fact will somehow be communicated to the switch, 
> perhaps in some status bit in packet headers, and the switch will 
> then send all traffic to the NIC port.  Obviously, from what you say, 
> this assumption is incorrect and I need have no concerns about my 
> server getting overloaded with extraneous traffic.

About the only thing that the client computer can to to effect what is 
or is not sent to it (aside from doing some very nasty things with ARP) 
is to enable Spanning Tree Protocol and mis-configure it and or allow 
loops in the network.  If you want to have a discussion about STP, just 
say the word.

> But that leads me to ask the question:  How do Linux network sniffing 
> utilities (which also use promiscuous mode) manage to pick up all 
> traffic?

In short, they do not.  The Linux (or what ever) networking sniffing 
utilities only see the traffic that comes to the NIC its self.  That is 
why if you want to sniff a switched network you either need to put a Hub 
in-line or use a SPAN / Mirror port on a switch.  This way, all the 
traffic makes it to the Linux (or what ever) system's NIC in promiscuous 
mode.

Remember that switches and bridges will (by default) only send traffic 
to all ports if they do not know where the destination MAC is.  Thus if 
they do know where the destination MAC is, they will send it only to the 
destination MAC, *NOT* all ports.



Grant. . . .

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/