Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 59 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Hardwarearrow device/system selection
EH-Net
May 22, 2013, 09:05:16 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: device/system selection  (Read 7601 times)
0 Members and 1 Guest are viewing this topic.
Determ
Newbie
*
Offline Offline

Posts: 23


View Profile
« on: December 15, 2011, 07:09:47 AM »

What kind of device is best to use if I want do "duplicate" and transfer network traffic from one remote facility to other, where analysis will be done?

So I'm looking for best "out-of-box" rack-cabinet appropriate device, sufficiently effective for being placed between switch and router.
Logged
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #1 on: December 15, 2011, 08:18:34 AM »

What kind of data are we talking about? Databases? Files? Or are you talking about replication at a lower level? Are you trying to de-dup before you transfer over the network?
Logged

Agoonie
Full Member
***
Offline Offline

Posts: 176



View Profile WWW
« Reply #2 on: December 15, 2011, 09:55:42 AM »

Wouldn't you just setup port mirroring and monitor everything from that port?  You could setup an appliance or a computer with wireshark,tcpdump, dsniff,etc, right?
Logged

OSCE, OSCP, OSWP, CISSP, GPEN

www.agoonie.com
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #3 on: December 15, 2011, 09:57:08 AM »

Good point, misread the question. Port mirroring over a WAN might be tough unless the bandwidth is significant.
Logged

mambru
Jr. Member
**
Offline Offline

Posts: 98


View Profile
« Reply #4 on: December 15, 2011, 10:11:40 AM »

Have you tried a tap?

http://www.flukenetworks.com/enterprise-network/network-monitoring/Tap-Solutions

http://www.network-taps.eu/products/products_networktaps.php
Logged
Determ
Newbie
*
Offline Offline

Posts: 23


View Profile
« Reply #5 on: December 16, 2011, 09:30:05 AM »

Have you tried a tap?

Yes, inline aggregating tap with filter option is needed, but do I get a device with router capabilities. Traffic should be send over WAN, but without intervention to existing (primary) router.
« Last Edit: December 17, 2011, 12:34:52 PM by Determ » Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #6 on: December 17, 2011, 03:53:59 PM »

Good point, misread the question. Port mirroring over a WAN might be tough unless the bandwidth is significant.

Not really. I used to work in a central data center for an auto company. All the plants had mini-data centers, but they got all their data from the centernal location. We had network genral sniffers and 4tb infinistreams attached to the network via span ports off cisco 6500s. the infinistreams rolled every 12 hours, and we never had complaints about performance.
Logged

OSWP, Sec+
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #7 on: December 17, 2011, 03:55:46 PM »

Have you tried a tap?

Yes, inline aggregating tap with filter option is needed, but do I get a device with router capabilities. Traffic should be send over WAN, but without intervention to existing (primary) router.

If I understand that right, you want the traffic needing to be watched to go out over the exiting WAN connection without going through the existing border router? can you create down time to set things up?
Logged

OSWP, Sec+
Determ
Newbie
*
Offline Offline

Posts: 23


View Profile
« Reply #8 on: December 22, 2011, 02:57:54 PM »

If I understand that right, you want the traffic needing to be watched to go out over the exiting WAN connection without going through the existing border router? can you create down time to set things up?

Yes.

Also I have time to set-up things, it's not continuous process 24/7. For the beginning would be ok, if the device (tap) could have option to save filtered traffic and send it via smtp on every X hours. In that way the device could be plugged directly in current switch. Ofcourse I don't know if I get such smart Tap device (having laptop in rack for that is not an option).
Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 1163


View Profile WWW
« Reply #9 on: December 22, 2011, 04:14:19 PM »

maybe not having a laptop, but if you could drop a full size server, one that looks like it belonged maybe.

Actually I was thinking more along the lines of how I had something set up in the past. Had a facility in rural area that could only get 1 dsl line. It was a PITA just to get that much. A partner company made a deal with a 3rd company who came in and set up gear.

I had to figure out how to have 2 secure networks seperated on the same DSL line. Connection went DSL hand off (DSL Modem with built in firewall and router), cisco pix for one network, linksys running dd-wrt for the other as their gateways, and then they did Site to Site VPN from those.

Was thinking maybe put an outer-edge device, then the border router, with your sniffer hooked into the outer edge device and the network with span port. lock it down tight with firewall rules.
Logged

OSWP, Sec+
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.085 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.