Community discussions

MikroTik App
 
User avatar
zlobster
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 63
Joined: Sun Nov 20, 2016 2:47 pm

Sniffing traffic with port mirroring

Sat May 06, 2023 6:18 pm

Hiyall!

How can one introduce a MT device on the ETH cable between 2 hosts and use port mirroring to capture all the bidirectional traffic between those two?

I'm talking about ROS7(.9) here, both with MT devices with and without switch chips.

Any help is highly appreciated!
 
User avatar
Buckeye
Forum Veteran
Forum Veteran
Posts: 893
Joined: Tue Sep 11, 2018 2:03 am
Location: Ohio, USA

Re: Sniffing traffic with port mirroring

Sat May 06, 2023 7:45 pm

Port mirroring is a switch ASIC feature, so I don't think you can mirror with an MT device without a switch. See Bridge-based port mirroring

And mirroring is different than capturing. It is essentially a "tap" for another device that will capture the traffic (e.g. something running wireshark or dumpcap). You may want to watch this Chris Greer video where he uses a Raspberry Pi 4 to capture, but you can use a PC as well).

What exactly do you want to do?
 
User avatar
zlobster
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 63
Joined: Sun Nov 20, 2016 2:47 pm

Re: Sniffing traffic with port mirroring

Sat May 06, 2023 7:58 pm

I'll be capturing the traffic between the two hosts with a laptop whose' NIC is in promiscuous mode. I'll be more like a one time event, so no fancy setups are needed, but speeds might reach near few hundred Mbps for a few minutes.
 
User avatar
Buckeye
Forum Veteran
Forum Veteran
Posts: 893
Joined: Tue Sep 11, 2018 2:03 am
Location: Ohio, USA

Re: Sniffing traffic with port mirroring  [SOLVED]

Sat May 06, 2023 8:41 pm

Here is the relevant documentation: https://help.mikrotik.com/docs/display/ ... tMirroring

I have never used this feature, I have a CSS106-5G-1S (RB260GS) with SwOS that I use as a network tap, and it is more flexible.

Here's a youtube video (in Dutch?) Mikrotik port mirror configuration where the configuration begins. The source is one of the ports you want to see traffic on, the destination is the mirror port you will be monitoring from.

The google translation of the video description to English is:
How can you see all traffic on a particular interface with your PC?
In this tutorial I will show you how to configure port mirror on the Mikrotik router.
 
User avatar
zlobster
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 63
Joined: Sun Nov 20, 2016 2:47 pm

Re: Sniffing traffic with port mirroring

Sat May 06, 2023 8:58 pm

Hmm, pretty straightforward! Thanks!

Assuming all is implemented correctly and the switch really captures ingress and egress port traffic, it should work just fine for my needs. In my case it should be simple because I only have 2 hosts on the same switch, so what's egress traffic for one should be ingress for the other and vice versa.

I'd still appreciate a similar solution with bridges, for when I don't have a MT device with a switch chip in it.

Who is online

Users browsing this forum: Ahrefs [Bot], Bing [Bot], Google [Bot], pmcsill and 115 guests