Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    APU1D4 as passive network sniffer?

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jeffhammett
      last edited by

      I have a spare APU1D4 laying around that is no longer being used as a router. I was looking to buy a network tap, but am wondering if I could easily configure it as an appliance with pfSense to do what I'm looking for.

      Basically I want one interface to connect to a switch or router with internet access. The second interface would connect to a computer and I want to mirror all of the traffic from that second interface connected to the computer to the third interface and put a packet capturing system on it.

      I think this could be accomplished by bridging the two interfaces, but I'm not sure.

      Anyone done something like this with pfSense? If so any tips on how to go about it?

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Use a switch. Blank VLAN for both sides and a mirror port going to the APU.

        You could install pfSense or just FreeBSD and run a circular tcpdump process.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • J
          jeffhammett
          last edited by

          I need something like this http://www.dual-comm.com/port-mirroring-LAN_switch.htm

          Something I can carry in my bag and put in line between a computer and all other networking gear and then easily connect another computer to sniff, watch traffic, etc.

          But since I have the spare APU, I'm wondering if I can repurpose this hardware without spending more money.

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            It's not a switch and you shouldn't use a router to do a switch's job. But look at bridging two of the interfaces. Not sure if you can tcpdump the bridge members or not.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • ?
              Guest
              last edited by

              A small switch with a mirrored port is able to get for less than $100.
              Netgear GS105Ev2
              Netgear GS108Ev2

              So if the network tap is able to get for $59, take it! Together with a laptop, because it is USB powered
              you could not get it better in my eyes. And together with WINDUMP and WireShark you might be able
              to sniff what you want and on top you could dig into the stored captured packets.

              The APU1D4 could be sorted with FreeBSD or a Linux version of your choice likes CentOS
              that came hardened by default and for Linux you may able to get many programs for free
              of charge and easy to install if you are often on the road.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.