I would like to tcpdump
all traffic that my router does when it makes a firmware update.
So I have taken a HP ProCurve 1800-8G switch and mirrored port 7 to port 8.
I have connected:
- Internet connection in port 6
- routers WAN port in port 7
- Linux host running
tcpdump
in port 8
I suppose the router have a dhcp client on the WAN interface.
However I don't see any activity. Not even the switch leds show activity for port 6 and 7.
Question
Do I have to configure something more in the switch in order use it as a network tap?
Update
Maybe it is the cables that are the problem? The router uses RJ11, so how should the RJ11 pins be connected to the RJ45 pins?
The ones I am using now are from an answering machine for port 6 and port 7.
____
|
HP ProCurve 6|---------------- Internet Uplink -------------- (Internet)
1800-8G | :
Switch | : <== (router-to-uplink path before tap)
(as a tap) | :
7|---------------- Router WAN port (downlink) --- (local n/w)
|
8|------------ Linux Host (with tcpdump)
____|