Sponsored Content
Special Forums IP Networking tcpdump and promiscuous mode (on Linux and HP-UX) Post 302171535 by Smiling Dragon on Thursday 28th of February 2008 05:25:32 PM
Old 02-28-2008
It switches modes when it's run, rather than at install time
The main effect of running in this mode is an increase in network traffic through the card (it's likely to cause a small increase in CPU load too).
If you completely overwhelm the card, you could potentially start dropping packets, inbcluding ones genuinly destined for this server - not very likely to happen with modern hardware though.

No major security concerns but one could make the case that accepting more data in over the NIC increases one's exposure to potential threats. Not exactly a biggie though Smilie
 

5 More Discussions You Might Find Interesting

1. IP Networking

promiscuous mode machines

/* SCO OpenServer 5 */ anyone know an effective way to tell what machines, if any, are running in promiscuous mode?? e0- (1 Reply)
Discussion started by: LowOrderBit
1 Replies

2. SuSE

Convet Linux OS from text mode to graphic mode

Hi All, I used to have my suse linux(VM) server in graphic mode but not anymore since morning. I cant rolback since i loose somuch work. Any idea how to it back to normal. Thanks (6 Replies)
Discussion started by: s_linux
6 Replies

3. AIX

promiscuous mode AIX

Hi Guys, What do I need to do to set an physical adapter to promiscuous mode? The networkport is already spanned/mirrored. Is this also possible when there is an virtual nic (through vios) configured? regards, Randy (7 Replies)
Discussion started by: raba
7 Replies

4. UNIX for Dummies Questions & Answers

Will Linux force NIC into promiscuous mode?

Right now I have a computer that I want to use as the monitor for my network. It's currently running Windows 7, and so as I understand it the NIC won't monitor all the traffic on the network. So my question is, if I install Linux on this computer will I be able to force the NIC card into... (1 Reply)
Discussion started by: iJeydon
1 Replies

5. Red Hat

Interface goes into promiscuous mode

Hi all, I am using a Linux VM. Once the node boots up, I am able to access it and it is able to ping its default gateway. At that time, the config is; eth1 Link encap:Ethernet HWaddr 00:50:56:01:01:FB inet addr:142.133.174.246 Bcast:142.133.175.255 ... (1 Reply)
Discussion started by: Junaid Subhani
1 Replies
tttview(1)								net								tttview(1)

NAME
tttview - Tele Traffic Tapper viewer- a viewer program for remote, real-time, graphical traffic-monitoring. SYNTAX
tttview [-addr recv_addr] [-mcastifaddr addr] [-multicast] [-port recv_port] [-probe addr] [-yscale (K|M|n)] DESCRIPTION
tttview is the viewer program in the ttt program suite. tttview displays traffic-data collected on a remote host by tttprobe. To run tttview, it is not necessary to be "root". The ttt program suite is yet another descendant of tcpdump but it is capable of real-time, graphical, local and remote traffic-monitoring. It won't replace tcpdump, rather, it helps you find out what to look into with tcpdump. OPTIONS
-addr recv_addr Specifies the local address. Only useful for multicast addresses. If omitted, "224.8.8.0 is used as default. -mcastifaddr addr Specifies the multicast interface address. Only useful when an interface is selected to join a multicast group. -multicast Shorthand for the default multicast destination "224.8.8.0". -port recv_port Specifies the udp port number to receive traffic-data from a remote tttprobe. If omitted, port 7288 is used as default. -probe addr Specifies the address of a probe. Only useful to select one among multiple probes. -yscale ('K'|'M'|n) change the scale of y-axis. 'K' and 'M' represent 1000 and 1000000 respectively. EXAMPLES
Remark: "hostA" is allways the host where traffic-data is collected with tttprobe and "hostB" is allways the host where the traffic-data is displayed with tttview. point-to-point monitoring: hostA: tttprobe hostB hostB: tttview or: hostA: tttprobe ip_of_hostB hostB: tttview multicast: when using the default multicast address: hostA: tttprobe -multicast hostB: tttview -multicast this is equivalent to: hostA: tttprobe 224.8.8.0 hostB: tttview -addr 224.8.8.0 AUTHORS
tttview was written by Kenjiro Cho < kjc@csl.sony.co.jp>. This manual page was written by Thomas Scheffczyk <thomas.scheffczyk@verwaltung.uni-mainz.de>, for the Debian GNU/Linux system (but may be used by others). SEE ALSO
ttt(1), tttprobe(1) Kenjiro Cho 1.7 tttview(1)
All times are GMT -4. The time now is 03:14 PM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy