This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

I work with industrial control systems. I often use an old non switching hub to monitor traffic between several devices, but I now have a problem where this would not be appropriate.

It is a network with bandwidth problems, and the central 100MB switch is routing raw ethernet packets between several different ports, as well as some ordinary IP traffic.

I need to find the bottlenecks and who is using most bandwidth etc...putting a hub in place of a switch is going to completely change the situation.

I know 'managed' switch have a lot of extra config possibilities, is there any way I could eg. monitor traffic on a GB managed switch with one port specially configured to output to WireShark?

Would it be realistic?

asked 12 Jul '17, 07:35

RogerIrwin's gravatar image

RogerIrwin
11113
accept rate: 0%


This is called port mirroring or spanning, see here for info and have a look at the Wireshark wiki page on Ethernet Capture for info on how to capture on a mirror port.

permanent link

answered 12 Jul '17, 07:47

grahamb's gravatar image

grahamb ♦
19.8k330206
accept rate: 22%

Thanks, some very clear explanations at the end of those links.

(12 Jul '17, 08:14) RogerIrwin
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×100
×86
×57
×32
×11

question asked: 12 Jul '17, 07:35

question was seen: 4,284 times

last updated: 12 Jul '17, 08:14

p​o​w​e​r​e​d by O​S​Q​A