Nosey rosey networking
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Other forums
- :
- Tech Help - Software/Hardware etc
- :
- Nosey rosey networking
Nosey rosey networking
23-12-2023 12:03 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Is the feed from the BT ONT pure ethernet?
If I put a (dumb-ish) switch (with some suitable configuration, and assuming the switch can SPAN/mirror ports) between the ONT and the router would it be possible to do packet capture between the home network with a device hanging off the mirror port?
Just asking if anyone has tried similar with a fibre install (before I go buying/spending).
Re: Nosey rosey networking
23-12-2023 9:01 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@greygit1 I don't see why it wouldn't work, switches operate at Level 2 so should happily pass the PPPoE discovery and connection. You will need a 'managed' switch to be able to do the port mirroring. The problem you will have though, is that the switch UI will not be accessible from your LAN network. In order to access the switch configuration you will need to connect a device directly to it with a static IP (in the default subnet for the switch).
Running a separate cable from the switch back to a LAN port on the router MAY allow the switch to get a LAN IP via DHCP and resolve the access problem, but whether that would cause other problems I'm not sure ?
I actually have a Netgear GS105E so one of these days I may just try...
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
Re: Nosey rosey networking
23-12-2023 1:21 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Could this configuration also be used in situations where the ONT and router have to be further apart than the usual theoretical ethernet limit of 100 metres allows? eg could a 150 metre cable run be split in to two 75 metre sections with the switch acting as a repeater?
I also have a Netgear GS105E, (though no FTTP to test on), so would be interested in your results.
Re: Nosey rosey networking
23-12-2023 1:28 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@Mr_Paul in theory , yes. The 100m limit is per segment, adding a switch would break it into two segments.
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
Re: Nosey rosey networking
23-12-2023 1:55 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
As an alternative method, if you happen to be using pfSense as your router, that has built-in packet capture which can be configured to do almost anything, and integrates nicely with wireshark for detailed analysis
Re: Nosey rosey networking
23-12-2023 10:15 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Obviously (?) the switch would have to be a managed type (to setup the outlined). But managed switches have tumbled in price. It would require some considered setup (along with an associated device capturing the mirrored traffic from the mirrored port). There has to be a separate devive to record the traffic on the mirrored port.
Why do I ask? Seen it done before (in a corporate network, with very much more expensive hardware). And that required functionality now appears to have filtered down to the SOHO/consumer level.
Re: Nosey rosey networking
23-12-2023 10:55 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Of course. Otherwise how do large-ish buildings have wired ethernet all over their place which actually works? L2 (and L1) devices breaking up the cable runs.
Re: Nosey rosey networking
24-12-2023 7:10 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Thick Ethernet ? 😐
Re: Nosey rosey networking
25-12-2023 8:15 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Isn't that also subject to the maximum distance (~100m) between nodes?
Re: Nosey rosey networking
25-12-2023 8:27 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
500m but can go further using Extenders or Bridge.
Re: Nosey rosey networking
25-12-2023 8:32 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I think my (proposed) idea isolates the monitoring/listening device doing the packet capture/monitoring from the general WAN (before NAT, no assigned WAN address, in its own isolated LAN, only accessible on a LAN, with other possibilities). The device capturing the traffic has no WAN access; the WAN has no access to that device. It is just sniffing stuff coming in and out of a location with an ethernet connection. That is its only purpose.
A (lucky) malformed IP packet could crash that system via the ethernet port, but it'd be a reboot and start monitoring again?
Eggs in one basket?
Re: Nosey rosey networking
28-12-2023 12:41 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I've got a new TP-link gigabit switch arriving.
FYI - the model numbers between TP-link and Netgear appear to be a switch of the first two characters (the TP-link version is SG1050E). I'm suspecting the internal gubbins is identical, and it is only the external casing and badging that is different.
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Other forums
- :
- Tech Help - Software/Hardware etc
- :
- Nosey rosey networking