sniffing traffic

Collecting all traffic from a mirror port on a switch is trivial.

For it to work, the switch must be set to transmit packages from one port to another. Check that you are mirroring the ports that you are interested in. And then on the machine connected to the mirror port

tcpdump -s 0 -i eth0 -w mycap.pcap -C 150

The sniffer machine usually have multiple ethernet interfaces. One (or more) for sniffing, and one for normal access (eg. management interface).

The above is the quick version, which would usable most places. For more “professional” use, look into security onion. Simple to install, and does a lot of IDS tricks.

