Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
You need to be careful when using Y shock to capture packets or frames from a network.
You need to think about how traffic flows through a network and make sure that you capturing in the
right part of the network.
So as an example if P.S. One opens up a browser and connects to the server where do you need to capture
the traffic.
Now it's obvious that you may capture here or make capture here but what happens if you capture over
here.
Will you see the traffic sent from the client to the server.
Notice we are seeing a whole bunch of traffic here.
We're seeing the GOP we seeing spanning tree.
We see other protocols but let's filter for HDP.
At the moment we see no HDP traffic what happens when P.S. 1 opens up a browser to the server so I'll
close this down and let's open up a browser and goatee tanned wandered one at 100.
So the server do we see any HP traffic and the answer is No.
If I clear the filters I'll see a whole bunch of traffic so as an example I can see DNS.
So there's DNS queries.
So let's filter for DNS notice the client 10 1 1 1 center DNS query you can see query here to the DNS
server the source IP addresses 10 1 1 1 destination is 10 1 1 2 5 4.
Now in this topology the router is acting as a DNS server.
This is a Cisco router so show version here shows me that I'm running Cisco.
IOW software on this road.
If you're not familiar with Cisco again you get free access to my CCN and a course.
So that'll teach you a whole bunch about Cisco riders but you don't need to know that to use Y shock.
But if you want to be a serious network engineer I strongly suggest that you learn about Cisco because
Cisco the biggest vendor out there but what I've done here.
A top show run pipe include DNS.
I have setup this rota as a DNS server through this command IP DNS server.
Now these commands may be confusing so let me show you that the router is also acting as a DHS piece
server or dynamic Host Configuration Protocol server.
In other words it's allocating IP addresses to clients dynamically.
The pieces are not configured with static ip addresses they dynamically get IP addresses from the DHB
server.
So this allows me to configure the road as a DHEA piece of.
And this command allows me to create entries in the DNS server running on this router that says genus
3 dot com has this IP address so as an example if I pinged Eunice 3 dot com that resolves to this IP
address domain name server or domain name system DNS allows us to resolve easy to read names to IP addresses.
This genus 3 topology is not connected to the Internet.
It's running locally on my computer so genius free dot com.
If you surf from an Internet connected device will take you to the actual genius 3 server.
But in this example it's simply taking us to this server in the topology.
Now what I'll do is stop this why shock capture and I'll save this
basic why shock capture 2 so you can also once again have a look at this capture if you want to but
notice here that the client is sending a DNS request to the server.
The reason this was captured is we were capturing traffic on this link and the PRC is sending a DNS
request to the router which is the DNS server
source MAC addresses the P.C. destination address is the router
we can prove that once again by going to the router and I can use the command show interface gigabit
zero slash zero.
Notice the MAC address of this rowdies.
This.
And that's them.
Destination MAC address of the frame.
So the P.C. sent a DNS request to the router source IP addresses the P.C. destination IP address is
the router.
I can prove that once again by going back to the writer remember I typed this command.
There's the MAC address.
There's the IP address of the router 10 1 1 2 5 4 source port number is an ephemeral or random or dynamic
port number.
Destination Port number is a well known port number 53 is the well-known port number for DNS.
So again Layer 2 frames Layer 3 packets Layer 4 segments.
In this case however it's a UDP or user data Graham protocol.
It's not TTP DNS in this example is using UDP source port again.
Destination Port.
Forget to layer 5 to 7 so top layers of the OS model.
You can see it's a standard query let's go through that Senate query
so the queries are in this example for Amazon.
So something was happening in the background but let's have a look for genius 3 dot com.
But notice windows just right out the gate is querying for a whole bunch of stuff including Bing dot
com.
So a whole bunch of queries there.
Let's see if we carry on a bunch of Microsoft and Nissan.
Keep going.
A lot of queries but this is the one I'm off to.
Notice genus 3 dot com.
So the windows.
P.S. In this example queried for genius 3 dot com and the server.
Hopefully at some point replies.
Here we go.
So reply back to the client.
Notice source port is 53 destination port is the femoral port used by the client.
Now notice different port numbers were used for different queries so the Bing query over here used this
source port number from the client.
I'd have to go back and find the genus 3 query.
There it is.
Notice 55 0 3 7 is the source port.
When the query was made when the server replies It's replying back to that port number and it tells
the client the IP address of the server.
So the router acting as a DNS server is telling the client June 23 dot com has this IP address 10 1
1 100 and then the client can initiate a session to the server but we don't see that if we capture traffic
on this link.
So again if I falter for HDP I see nothing in the output because the HDP traffic is sent directly from
the client to the server.
Why.
Because this is a switch it's important to remember that switches do not flood traffic once they know
the MAC addresses involved in a conversation
says an example if I type show Mecca address table notice we can see the MAC addresses that have been
learnt the switch has learnt about this MAC address on gigabit 0 0 it's also learnt about this MAC address
and it's learnt about this MAC address on gigabit 0 1.
Now when I sent traffic from the client so that could have timed out if I refresh that page notice it's
learnt about this MAC address on gigabyte 0 2.
Once the switch learns about the MAC addresses in the conversation.
This once again is the server and just in case you don't believe me.
Notice this is the MAC address of the server.
This is the HDP server over here noticed this MAC address was learnt on gigabit 02.
Once this switch has learnt about to the devices in the conversation.
It's not going to flood the frames out of other ports it's going to be switched directly between these
two hosts.
So the P.C. with this MAC address 0 0 0 c ending in DC D 7 you know the words this MAC address is gonna
have its traffic forwarded directly to the server and the server traffic is going to go directly back
to the P.C. so if you capture traffic on this link you won't see the conversation between the server
and the client.
That's why you need to either span a port or mirror a port on the switch to be able to see what's going
on or you need to have a network tap or something in the network where you can see the traffic.
You've gotta get to the traffic to your capturing device otherwise you won't see it.
So in the next video I'll show you how to do that.
Let's add a mirror to the topology so that we can actually see what's going on.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.