fooler: yes 2 nic's will work as a bridge. but the advantage of the tap in the URL is that even if the sniffer box goes down, connectivity is unaffected.
actually at work what is recommended is the NetOptics line. $1000 for the copper (10/100/1000baseT) version. i just can't get my hands on one, no ASEAN distributor... On Thu, Sep 18, 2008 at 8:28 PM, fooler mail <[EMAIL PROTECTED]> wrote: .. > with your given URL... he used 2 network cards inside its sniffer > server plus a network tap... he can still sniff packets inside his > sniffer server without using a network tap.. the simplest thing to do > is to let the two network cards act as a "bridge" as shown below: > > [host A nic 1] <-----> [nic 1 sniffer server nic 2] <----> [nic 1 host B] > > bridge is on layer 2 and it doesnt need an IP address thus it is > transparent between host A and B... > > but still i can sniff packets between host A and B without using a > sniffer server as shown above as long as there is another host joining > on the same network segment of host A and B in a switch environment... -- Orlando Andico +63.2.976.8659 | +63.920.903.0335 _________________________________________________ Philippine Linux Users' Group (PLUG) Mailing List http://lists.linux.org.ph/mailman/listinfo/plug Searchable Archives: http://archives.free.net.ph

