Or you can flood the CAM, or generate TCs so that traffic is flooded
because of unknown destination port.
-Carlos
marc edwards @ 5/8/2011 14:26 -0300 dixit:
> # 2 is the answer to question #1. In promiscuous mode with no SPAN set up,
> the traffic that will be sniffed is anything unicasted directly to PC
> attached, anything boradcasted/multicasted (if PC joins), and anything that
> is a unicast flood (basically a broadcast-- uncontrolled unicast).
>
> To monitor a specific device not on that port a monitor session will be
> needed.
>
> HTH
>
> Marc
>
> On Fri, Aug 5, 2011 at 4:42 AM, O B <obcert_at_gmail.com> wrote:
>
>> I have setup like this Win-XP PC(NIC turned into promiscuous mode) with
>> Ethereal connected gi 0/1 of Cisco SW. I don't have any monitoring port
>> configured on SW or port forwarding.
>>
>> 1. Can I able to watch in Ethereal what all PCs activity?
>>
>> 2. Sniffing does not work in switched networks? with exception of broadcast
>> & multicast?
>>
>>
>> Your thoughts are appreciated in advanced.
>>
>>
>> Blogs and organic groups at http://www.ccie.net
>>
>> _______________________________________________________________________
>> Subscription information may be found at:
>> http://www.groupstudy.com/list/CCIELab.html
>
>
> Blogs and organic groups at http://www.ccie.net
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html
>
>
>
>
>
>
>
-- Carlos G Mendioroz <tron_at_huapi.ba.ar> LW7 EQI Argentina Blogs and organic groups at http://www.ccie.netReceived on Fri Aug 05 2011 - 15:02:43 ART
This archive was generated by hypermail 2.2.0 : Thu Sep 01 2011 - 06:05:56 ART