Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Monitoring data passing through a Cisco router

Thread Tools
 
Search this Thread
 
Old 23 June 2003, 10:54 AM
  #1  
akshay67
Scooby Regular
Thread Starter
 
akshay67's Avatar
 
Join Date: Nov 2001
Posts: 2,342
Likes: 0
Received 0 Likes on 0 Posts
Question

Can one monitor the data content passing through a Cisco router much in the same way you'd SPAN a port on a Cisco switch?

If so, how is this done? Just a high-level outline will be fine.

Cheers!
Old 23 June 2003, 12:17 PM
  #2  
BazH
Scooby Regular
 
BazH's Avatar
 
Join Date: Jul 2002
Posts: 274
Likes: 0
Received 0 Likes on 0 Posts
Cool

Turn on netflow and get yourself some software to read it
Old 23 June 2003, 02:21 PM
  #3  
akshay67
Scooby Regular
Thread Starter
 
akshay67's Avatar
 
Join Date: Nov 2001
Posts: 2,342
Likes: 0
Received 0 Likes on 0 Posts
Post

Does Netflow allow you to read the packet payload?
Old 23 June 2003, 03:55 PM
  #4  
BazH
Scooby Regular
 
BazH's Avatar
 
Join Date: Jul 2002
Posts: 274
Likes: 0
Received 0 Likes on 0 Posts
Post

Not as far as i'm aware, but if someone can enlighten me qoute "it resorts to compromises and heuristics"
Old 23 June 2003, 04:30 PM
  #5  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

http://www.cisco.com/univercd/cc/td/...ol/nfwhite.htm
Old 23 June 2003, 09:43 PM
  #6  
dsmith
Scooby Regular
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

Netflow is used mainly as it implies for monitoring flows. Source/Destination and Bandwidth. Often by Subnet rather than host addresses - for example for monitoring traffic usage between large parts of a company, between ISPs etc etc.

If you want to look in more detail at individual packets careful use of debug ip packet and access lists can help. It is extremely easy to overwhelm the router though. Some platforms (e.g. Cat 6K/MSFCs) hardware switch all but the initial packets so the routing engine wont see them. Forcing it to software switch every packet, so they can be inspected, can result in huge performance hits (to the point the network becomes unusable). Of course on low-use networks you may be get what you need this way

In short there is no way to "span" a router interface like you would a swicth port and copy all packets to a sniffer. If its a LAN port the best route is to simply span the source switch port if possible. In-line probes are also available for most LAN types. For true sniffing of a WAN port you'll need either a suitable in-line probe or something like the Agilent Advisor with relevant interfaces. Not Cheap, though I believe they can be hired.

Deano

[Edited by dsmith - 6/23/2003 9:45:18 PM]
Old 23 June 2003, 09:50 PM
  #7  
David_Wallis
Scooby Regular
 
David_Wallis's Avatar
 
Join Date: Nov 2001
Location: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Posts: 15,239
Likes: 0
Received 1 Like on 1 Post
Post

or just cheat and shove a hub and crossover cable in?

We do this when having to use our fluke to sniff packets on our routers.. (ok well our networks team do..)

David
Old 23 June 2003, 11:02 PM
  #8  
carl
Scooby Regular
 
carl's Avatar
 
Join Date: May 1999
Posts: 7,901
Likes: 0
Received 0 Likes on 0 Posts
Post

or just cheat and shove a hub and crossover cable in?
Assuming it's an Ethernet network you're trying to sniff. Would be a bit more difficult (and expensive) if you're trying to sniff an STM-64 POS interface.

dsmith -- I'm sure you know, but lots of Cisco boxes fall over due to the performance hit when you attempt to fast switch (route first packet, switch the rest). In fact if you want to get close to rated capacity then dCEF is the only way to do it -- it maintains a separate set of CEF tables that are populated from the routing table. IIRC the only CEF that GSRs do is dCEF.

[Edited by carl - 6/23/2003 11:05:23 PM]
Old 24 June 2003, 09:06 AM
  #9  
SiCotty
Scooby Regular
 
SiCotty's Avatar
 
Join Date: Jan 2001
Posts: 442
Likes: 0
Received 0 Likes on 0 Posts
Post

Cat 6k now uses CEF switching as well.

Si
Old 24 June 2003, 09:31 AM
  #10  
dsmith
Scooby Regular
 
dsmith's Avatar
 
Join Date: Mar 1999
Posts: 4,518
Likes: 0
Received 0 Likes on 0 Posts
Post

I was indeed generalising fast switching with all other hardware switching types as getting in the way if your attempting to debug packets.

Cat6k pushes it so far into hardware that snmp stats for vlan interfaces are woefully inaccurate.

Deano


Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Sam Witwicky
Engine Management and ECU Remapping
17
13 November 2015 10:49 AM
T.K
General Technical
10
02 October 2015 11:35 AM
Davalar
General Technical
19
30 September 2015 08:54 PM
Cdm172
Was it you?
0
28 September 2015 05:41 PM
Nick_Cat
Computer & Technology Related
2
26 September 2015 08:00 AM



Quick Reply: Monitoring data passing through a Cisco router



All times are GMT +1. The time now is 05:16 AM.