The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > IP Networking
Google UNIX.COM
Home Forums Register Rules & FAQ Members List Arcade Search Today's Posts Mark Forums Read


IP Networking Questions involving TCP/IP, Routers, Hubs, Network protocols, etc go here.


Other UNIX.COM Threads You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Kernel Mode Linux 2.6.25_001 (For Linux 2.6 branch) iBot Software Releases - RSS News 0 04-24-2008 01:00 AM
Kernel Mode Linux 2.6.24_002 (For Linux 2.6 branch) iBot Software Releases - RSS News 0 02-12-2008 09:30 PM
Kernel Mode Linux 2.6.24_001 (For Linux 2.6 branch) iBot Software Releases - RSS News 0 02-03-2008 07:50 AM
How to get back my linux gui mode? Vishnu UNIX for Dummies Questions & Answers 2 11-22-2002 06:18 AM
promiscuous mode machines LowOrderBit IP Networking 1 09-18-2001 10:06 PM

Reply
 
Submit Tools LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 02-25-2008
Registered User
 

Join Date: Feb 2008
Posts: 8
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!Spurl this Post!
tcpdump and promiscuous mode (on Linux and HP-UX)

Hallo,

I want to use tcpdump to analyze the NTP traffic on some of my machines. The machines that I want to analyze run HP-UX and linux. To use tcpdump 2 packages are required Libpcap and Tcpdump. I know that tcpdump (libcap?) sets the network interface to promiscuous mode. I have some questions:

1) does the installation itself of libcap/tcpdump set the interface to promiscuous mode mode or does tcpdump set the interface to promiscuous mode when it is started and then it sets back to non promiscuous mode when it is stopped?

2) If the promiscuous mode is activated at installation time, how to deactivate it when I am ready with my analysis? Is it enough to de-install the 2 packages?

3) How to check if the promiscuous mode is activated without installing extra packages? (I do not see anything in the logs (at least on HP-UX) and nothing with dmesg)

4) which are the drawbacks with an active promiscuous mode? I guess higher latency time (?), what about security?, what else?

Most important for me is what happens with the HP-UX machines.

Thanks a lot.
Reply With Quote
Forum Sponsor
  #2 (permalink)  
Old 02-28-2008
Smiling Dragon's Avatar
Disorganised User
 

Join Date: Nov 2007
Location: New Zealand
Posts: 562
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!Spurl this Post!
It switches modes when it's run, rather than at install time
The main effect of running in this mode is an increase in network traffic through the card (it's likely to cause a small increase in CPU load too).
If you completely overwhelm the card, you could potentially start dropping packets, inbcluding ones genuinly destined for this server - not very likely to happen with modern hardware though.

No major security concerns but one could make the case that accepting more data in over the NIC increases one's exposure to potential threats. Not exactly a biggie though
Reply With Quote
Google UNIX.COM
Reply



Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:36 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger

Search Engine Optimization by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102