Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 87 guests and 2 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Hardwarearrow device/system selection
EH-Net
May 26, 2012, 08:24:17 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: device/system selection  (Read 3912 times)
0 Members and 1 Guest are viewing this topic.
Determ
Newbie
*
Offline Offline

Posts: 23


View Profile
« on: December 15, 2011, 07:09:47 AM »

What kind of device is best to use if I want do "duplicate" and transfer network traffic from one remote facility to other, where analysis will be done?

So I'm looking for best "out-of-box" rack-cabinet appropriate device, sufficiently effective for being placed between switch and router.
Logged
cd1zz
Sr. Member
****
Offline Offline

Posts: 393


View Profile WWW
« Reply #1 on: December 15, 2011, 08:18:34 AM »

What kind of data are we talking about? Databases? Files? Or are you talking about replication at a lower level? Are you trying to de-dup before you transfer over the network?
Logged

Agoonie
Full Member
***
Offline Offline

Posts: 144



View Profile
« Reply #2 on: December 15, 2011, 09:55:42 AM »

Wouldn't you just setup port mirroring and monitor everything from that port?  You could setup an appliance or a computer with wireshark,tcpdump, dsniff,etc, right?
Logged

OSCE, OSCP, OSWP, CISSP, MEH...
cd1zz
Sr. Member
****
Offline Offline

Posts: 393


View Profile WWW
« Reply #3 on: December 15, 2011, 09:57:08 AM »

Good point, misread the question. Port mirroring over a WAN might be tough unless the bandwidth is significant.
Logged

mambru
Jr. Member
**
Offline Offline

Posts: 98


View Profile
« Reply #4 on: December 15, 2011, 10:11:40 AM »

Have you tried a tap?

http://www.flukenetworks.com/enterprise-network/network-monitoring/Tap-Solutions

http://www.network-taps.eu/products/products_networktaps.php
Logged
Determ
Newbie
*
Offline Offline

Posts: 23


View Profile
« Reply #5 on: December 16, 2011, 09:30:05 AM »

Have you tried a tap?

Yes, inline aggregating tap with filter option is needed, but do I get a device with router capabilities. Traffic should be send over WAN, but without intervention to existing (primary) router.
« Last Edit: December 17, 2011, 12:34:52 PM by Determ » Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 999


View Profile
« Reply #6 on: December 17, 2011, 03:53:59 PM »

Good point, misread the question. Port mirroring over a WAN might be tough unless the bandwidth is significant.

Not really. I used to work in a central data center for an auto company. All the plants had mini-data centers, but they got all their data from the centernal location. We had network genral sniffers and 4tb infinistreams attached to the network via span ports off cisco 6500s. the infinistreams rolled every 12 hours, and we never had complaints about performance.
Logged

OSWP, Sec+
chrisj
Hero Member
*****
Offline Offline

Posts: 999


View Profile
« Reply #7 on: December 17, 2011, 03:55:46 PM »

Have you tried a tap?

Yes, inline aggregating tap with filter option is needed, but do I get a device with router capabilities. Traffic should be send over WAN, but without intervention to existing (primary) router.

If I understand that right, you want the traffic needing to be watched to go out over the exiting WAN connection without going through the existing border router? can you create down time to set things up?
Logged

OSWP, Sec+
Determ
Newbie
*
Offline Offline

Posts: 23


View Profile
« Reply #8 on: December 22, 2011, 02:57:54 PM »

If I understand that right, you want the traffic needing to be watched to go out over the exiting WAN connection without going through the existing border router? can you create down time to set things up?

Yes.

Also I have time to set-up things, it's not continuous process 24/7. For the beginning would be ok, if the device (tap) could have option to save filtered traffic and send it via smtp on every X hours. In that way the device could be plugged directly in current switch. Ofcourse I don't know if I get such smart Tap device (having laptop in rack for that is not an option).
Logged
chrisj
Hero Member
*****
Offline Offline

Posts: 999


View Profile
« Reply #9 on: December 22, 2011, 04:14:19 PM »

maybe not having a laptop, but if you could drop a full size server, one that looks like it belonged maybe.

Actually I was thinking more along the lines of how I had something set up in the past. Had a facility in rural area that could only get 1 dsl line. It was a PITA just to get that much. A partner company made a deal with a 3rd company who came in and set up gear.

I had to figure out how to have 2 secure networks seperated on the same DSL line. Connection went DSL hand off (DSL Modem with built in firewall and router), cisco pix for one network, linksys running dd-wrt for the other as their gateways, and then they did Site to Site VPN from those.

Was thinking maybe put an outer-edge device, then the border router, with your sniffer hooked into the outer edge device and the network with span port. lock it down tight with firewall rules.
Logged

OSWP, Sec+
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.218 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.