Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
So in this genus we topology I'm going to add a device that will allow me to capture traffic basically
as if I had a monitoring station in my network.
So let's pretend there's a boon to P.C. is a monitoring device.
I'm not actually going to use that for monitoring.
I'm going to use genus 3 to do it directly.
But let's pretend you were running why shock on the subway to P.S. I could as an example use a Windows
P.C. here rather than a Bunty but I'm going to simply capture the traffic this way.
So again if I start capturing on this link will I see the HP to be traffic from the P.C. to the server
or filter for HDP here.
Nothing at the moment.
On the client I'll refresh this page.
Don't see anything manually type it in.
Don't see anything.
Shut that down.
Open it up again try and connect to the server.
We don't see any HP traffic on this link but what I'm going to do now is span or mirror the port on
the switch so on switch one gonna go to global configuration mode to type monitor this is.
This goes by different terms.
It's known to span or monitor or mirror wing span is known as switched port analyzer.
We're going to use the term monitor here.
So I'm gonna monitor a session I'm going to give it a number one to specify the source interface as
gigabit zero slash zero.
So this interface is going to be the source and then I must say monitor session one destination interface
gigabit 0 3.
So source interface destination interface.
The switch is going to copy old traffic from this interface to this interface so let's prove that this
is the y shock capture from gigabit 0 3 to the boon to host.
In other words over here on the client refresh the page.
Notice I suddenly see HP traffic refresh the page again I see more HDP traffic so because I'm spanning
the port I can see the HDP traffic.
So if I had a monitoring station here.
So I was running a Windows computer or some other computer with why shot directly on it.
I'd need to spend the port like I've done here.
To be able to see the traffic
again network vendors use different terms.
My rowing monitoring span.
But notice show monitor session let's say session one you can see that we are capturing traffic in both
directions on this port and the destination port is gigabit.
0 3 cancellation is Native.
We're not adding any additional frames to the captures so you'll actually see the original frames here.
Notice source MAC address.
P.S. going to the server source IP address of P.S. to the server as a frame packet segment.
Random port number going to port 80 and you can see the actual request made there.
So if we look at the server response we can see for instance the PSG file.
Notice nothing was modified so with a browser it often caches the data locally so it doesn't rerecord
just all the data.
To save on bandwidth but if I shut that browser down open it up again and go to the server and I'll
go right down.
Again we see not modified so let's actually do this.
I'm going to open up a private window and go to the server that way to force it to do everything again.
So here we go.
Client request.
Here's the reply from the server and notice you can see all the data from the server so you can see
title of the web page.
You can see the actual text in the web page so in summary Be careful of way you capture traffic.
In this example we wouldn't see the traffic on this link or on this link unless we enabled port monitoring
or spanned the port.
In other words you need to get the switch to copy frames from this interface.
Out of this interface it wouldn't normally do that.
If traffic was going from the client to the server you have to enable the merging of traffic to be able
to see it on a switch with a hub.
You wouldn't have to do that a hub floods traffic out of all ports but a switch doesn't.
So once again don't forget you need to be careful where you monitoring traffic.
If you want to see what's going on as an example if you want to see what's going on on this side of
the network you want to put a probe or some device on that part of the network so that you can see what's
going on.
You could implement remote span where you copy traffic through a tunnel from one side of the network
to another but you need to be careful with that because of overhead and because of the amount of traffic
that you're going to be receiving so we'd be better to capture traffic locally if you can.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.