Networking Forums

Networking Forums > Computer Networking > Linux Networking > Adjusting Ethereal's Capture-Filters for Web-Address filtering?

Reply
Thread Tools Display Modes

Adjusting Ethereal's Capture-Filters for Web-Address filtering?

 
 
Felix Eggbert
Guest
Posts: n/a

 
      10-25-2004, 01:46 PM
Hello,

I guess this question must have been asked before but I haven't found
any answers. My boss has told me to find out which web addresses within
the company are surfed to when he is on holidays.

The network is handled by a w2k server. For the stations the server acts
as gateway whereby it is forwarding internet traffic to a router which
is connected to the dsl line. So every traffic passes the server. I
installed Ethereal and played around a little bit. I already found out
how to filter all traffic on port 80. But of course this only returns
the data traffic between the two computers ip-addresses.

I guess I have to filter just the requests of the workstations to the
dns server, haven't I? With this I could theoretically see which
addresses are to be solved, am I right? How do I do this/which port do I
filter for name resolution?

Thanks and best regards,

Felix Eggbert, Germany
 
Reply With Quote
 
 
 
 
James Knott
Guest
Posts: n/a

 
      10-25-2004, 03:19 PM
Felix Eggbert wrote:

> I guess I have to filter just the requests of the workstations to the
> dns server, haven't I? With this I could theoretically see which
> addresses are to be solved, am I right? How do I do this/which port do I
> filter for name resolution?
>


I think your best bet, would be to monitor the connection to the DSL. That
way, you can eliminate all local traffic. Get yourself a cheap hub (not
switch) to place between the router and DSL and connect your monitoring
computer. You'll then be able to monitor all traffic on the DSL, which you
can then capture, using port 80. More expensive routers & switches may
have a monitor port, which you could also use.

--

(This space intentionally left blank)
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to start Ethereal capture at network usage threshold? ryanlink@gmail.com Windows Networking 1 06-05-2006 03:25 PM
Can't launch ethereal--- bash: ethereal: command not found krakov@mailinator.com Linux Networking 1 06-20-2005 10:16 AM
IPSEC not blocking specific IP address per Ethereal Alfredo Windows Networking 13 04-21-2005 05:38 AM
MAC Address Filtering & Bandwidth Limiting based on MAC Address w.kinderman Linux Networking 0 11-11-2004 10:19 PM
MAC address filtering MN-500, allow unspecified MAC address? Tony Broadband Hardware 2 07-14-2004 05:18 AM



1 2 3 4 5 6 7 8 9 10 11