Felix Eggbert wrote:
> I guess I have to filter just the requests of the workstations to the
> dns server, haven't I? With this I could theoretically see which
> addresses are to be solved, am I right? How do I do this/which port do I
> filter for name resolution?
>
I think your best bet, would be to monitor the connection to the DSL. That
way, you can eliminate all local traffic. Get yourself a cheap hub (not
switch) to place between the router and DSL and connect your monitoring
computer. You'll then be able to monitor all traffic on the DSL, which you
can then capture, using port 80. More expensive routers & switches may
have a monitor port, which you could also use.
--
(This space intentionally left blank)
|