Tuesday, November 5, 2019

What method do YOU use to do a packet capture at 1Gbps? (Wireshark & hub vs port mirroring?)

I'm looking to start a discussion on here on what method(s) you would use to capture data from a device that MUST link at 1Gbps.

This would include what software and/or hardware you are using to do this.

My guess is this will be VERY situational, as in "Where are you trying to capture the data?" So I'll give a basic situation here that I'm looking for advice on capturing:

Currently I am using a Netgear DS104 Hub with my computer running Wireshark, but the limitations of the Netgear hubs are 10/100 only from what I could find. The 2 devices in question are also on the hub. This situation is working great to capture at 100Mbps.

My situation now requires that I connect the device at 1Gbps and capture traffic from that, but I just can't seem to find any hubs out there running at 1Gbps that are for sale.

What do you all use in this situation? A cheap smart switch with port mirroring? Do you trust you are getting absolutely everything with port mirroring? Do you know of where to obtain a 1Gbps hub? Or do you use a completely different method here? I'd love to hear!

Thank you in advanced for any help here!



No comments:

Post a Comment