BUILD a Packet Capture Appliance for $200! Raspberry Pi

แชร์
ฝัง
  • เผยแพร่เมื่อ 21 ต.ค. 2024

ความคิดเห็น • 60

  • @pedrojaviermunozgarcia3721
    @pedrojaviermunozgarcia3721 7 หลายเดือนก่อน

    Excellent configuration and a cost-effective solution!!

  • @conm9891
    @conm9891 2 หลายเดือนก่อน

    Bruhhhhh, Im relearning my packet skills and I was trying to find you last night. Said screw it went to bed, "ill google it tomorrow". And who tf shows up on my home feed. Thank you for all the knowledge Chris.

  • @ohasis8331
    @ohasis8331 2 ปีที่แล้ว +1

    That was made to look surprisingly easy as well as decent pricing.

  • @rubenmahecha1438
    @rubenmahecha1438 ปีที่แล้ว

    I loved this one , can't wait for the suricate one you mentioned :D

  • @monstroPT
    @monstroPT ปีที่แล้ว +1

    Hi, Chris!
    For when the follow-up? I'm dying here! 😀

  • @4b5urd.
    @4b5urd. 2 ปีที่แล้ว

    I had been kicking around the idea of how to do this with a pi, but didn't know if it would be possible essentially because the issue that you resolved with the netgear switch. I'll have to pick one up and give this a try. Thanks for putting your time into content like this. It is greatly appreciated.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      That little switch is worth it!

    • @jonpinkley2844
      @jonpinkley2844 ปีที่แล้ว +2

      That Netgear switch looks nice and portable. My favorite tap switch is the MikroTik CSS106-5G-1S due to its flexibility. For example it has port isolation so you can partition into two "independent" groups. I use 1-2 in one group and 3-4-5 in the second, and use port three as the "mirror/span" port with the capture device. Then you can mirror ingress on ports 1,2,4,5 to port 3 (I know, easy to overrun the mirror port and have packets dropped). The advantage of this it you can then put a router or other device (firewall, nat, vpn, tagging/untagging of vlans, etc.) and you can see what is going into the device under test as well as what comes out the other side. So you can see how packets are transformed, and look at latencies. Also, MikroTik has very extensive port counters, with counts of unicast, multicast and broadcast per port, as well as histograms of packet sizes sent/recieved for each port (64,65-127,128-255,256-511,512-1023,1024-1518,1519-max). The last one I bought on Amazon was in 2018 and the price was under $40, but now it is $49. It is also not as portable as the Netgear. If you are only mirroring a single port, the Netgear should be fine and is significantly cheaper.

  • @miguelk8768
    @miguelk8768 2 ปีที่แล้ว

    Looking forward for that monitoring video :) awesome work Chris!

  • @EricBrokeIt
    @EricBrokeIt 2 ปีที่แล้ว

    So when the world went into work from home chaos I built one of these almost identical to this. Mine has a POE hat, usb enclosure for a evo, and rather than a switch I picked up a qualcomm 1gig tap. Its perfect for WFH calls where I would have to run in to packet capture something, just throw it inline on the problem PC in the data closet and leave it there. Head home and remote into it. Great little solution.
    Great content as always Chris! Looking forward to the suricata video.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Fantastic Eric! It really is a sweet little box. I'm having a good time using it to monitor.

  • @zer001
    @zer001 ปีที่แล้ว

    Wow cool. I know dumpcap since 30 sec. and i love it. I see some opertunities on my way. Many Thanks for your great Videos.

  • @Closer80IT
    @Closer80IT 2 ปีที่แล้ว

    Years ago we used a Debian pc to capture the traffic over a 10gbit link. To save a capture sometimes took 30 minutes... LOL... The good old memories. Recently I used RPi to create a remote monitoring system for my customers. Zabbix on cloud and RPi deployed at customer site. Very handy tools!!

  • @hnasr
    @hnasr 2 ปีที่แล้ว

    Great work Chris! I want to try this soon.
    Will this also capture traffic between two devices communicating directly not going to WAN? Say my laptop is an HTTP server and my phone is connecting to it using laptop private IP and both the phone and laptop is connected to the eero wireless AP.
    I’m not sure if the frames will leave the Access point in this case (through the yellow cable) to be captured

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Hey Hussein! In that case no - at that vantage point, we wouldn’t see the wireless traffic because the eero won’t forward those packets out the wired interface. It would only do that if it has a reason to send the traffic out.

  • @pauljeyasingh
    @pauljeyasingh 2 ปีที่แล้ว

    Love your content Chris, Would like to check if there is any content around EDNS pcap.

  • @tranxn7971
    @tranxn7971 2 ปีที่แล้ว

    Hey Chris, thanks for the video ! I did not know about the dumpcap command, good finding.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Glad you liked the video

  • @arubajamaica8563
    @arubajamaica8563 2 ปีที่แล้ว

    Very interesting and achievable, thank you

  • @chrisoakleyfx
    @chrisoakleyfx 2 ปีที่แล้ว +1

    Love your content Chris, I'm still new to networking but I love watching content like this to see what's out there and absorb what information my newbie brain can handle 😄 your TCP and UDP deep dives with David Bombal were very interesting and informative even to someone like myself. Keep up the great work 😊

    • @utsavkataria96
      @utsavkataria96 2 ปีที่แล้ว

      Great, I am not alone xD. I almost have no clue what he is talking about. Just got him in recommended.

  • @CyberABE
    @CyberABE 2 ปีที่แล้ว

    Thank you Chris great Video!

  • @vyasG
    @vyasG 2 ปีที่แล้ว

    Thank you so much for this video. I have got to try this one to solve my intermittent WiFi issue. I'll couple my pi4 with Dualcomm ETAP to do something similar to this.

  • @MSUjgasmussen
    @MSUjgasmussen 2 ปีที่แล้ว

    Thank you Chris! Sharing with my network.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Thanks for sharing!

  • @cherriagana
    @cherriagana 2 ปีที่แล้ว +1

    Had to use a Profishark tap for my solution.
    Managed switches with a mac-adres that isn't registered on our company's network will make the main switch port go into shutdown mode.
    Was an oopsie moment when I tried to analyze a network problem on an industrial line and suddenly everything went down :p

  • @abhishekpatil5768
    @abhishekpatil5768 2 ปีที่แล้ว

    Incredible 🔥

  • @bergerMeister949
    @bergerMeister949 2 ปีที่แล้ว

    Great content Chris, I appreciate you showing how accessible this solution is. You mentioned Suricata in one of the comments, what are your thoughts on Suricata vs Snort?

  • @johndicarlo225
    @johndicarlo225 ปีที่แล้ว

    thanks dude

  • @pietstreet8311
    @pietstreet8311 2 ปีที่แล้ว

    Another good solution is a barebone PC with two ethernet ports. you can bridge the ports in linux and just can plug in the PC between your LAN and the device you want to examine.

  • @yohanmeier6061
    @yohanmeier6061 ปีที่แล้ว

    i do my probe capture with Raspberry it's top :-) thank you for idea

  • @barryfawthrop9962
    @barryfawthrop9962 2 หลายเดือนก่อน

    How did you configure the switch to monitor on port 5??

  • @yohanmeier6061
    @yohanmeier6061 2 ปีที่แล้ว +1

    I can add tools metrology as ntopng community version for graphics

  • @ChitChat
    @ChitChat 2 ปีที่แล้ว

    I've recently looked into SPAN and TAP solutions. Does this setup turn your Pi into a hardware TAP simply because it doesn't affect the system or more like an Adhoc SPAN setup? Thanks.

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Hey, no it doesn’t. The switch performs the span function and passes the traffic to the pi

  • @DarianCabot
    @DarianCabot 2 ปีที่แล้ว

    Love it 👍

  • @tlturner3
    @tlturner3 9 หลายเดือนก่อน

    What settings did you make for the rpi Ethernet port so that it's not sending data from it's self out the mirror port?

  • @KSax-ed9vy
    @KSax-ed9vy 2 ปีที่แล้ว

    Good stuff!

  • @TheStevenWhiting
    @TheStevenWhiting ปีที่แล้ว

    How do you get your VNC to be so quick and smooth. Its as slow as slow came be for me. I'm say right next to the Pi.

    • @TheStevenWhiting
      @TheStevenWhiting ปีที่แล้ว

      Adding
      hdmi_group=2
      hdmi_mode=82
      To the /boot/config.txt appears to have fixed it. As mentioned on a video titled Fix VNC raspberry pi slow (Can read more in the description)

  • @DM-qm5sc
    @DM-qm5sc 2 ปีที่แล้ว

    I know you explained it and I watched multiple times but I dont understand how and why you connected the pi, the switch and the "pf sense" the way that you did.

  • @lamjeri
    @lamjeri 2 ปีที่แล้ว

    Is it possible to use VLAN as a mirroring target? So that you could use the Pi as a server and have a VLAN interface on it for packet captures?

  • @jonpinkley2844
    @jonpinkley2844 ปีที่แล้ว

    Chris, this is a great video. Now that you have had the appliance running, how many times have you looked at the data, and how useful was it? With such a high percentage of data now being encrypted, is is still worth while to store the complete packet vs using the -s aka --snapshot-length to limit the capture to something less? Then you would still have src and dst addresses and protocols in use. While writing this, I wondered if there is a way to have only non-encrypted protocols stored with the full contents, but the encrypted protocols truncated. Or do you force clients to use forged certificates, so you can decode after the fact? And I doubt that would help with malicious hosts (iot, etc.) Have you thought of setting up the wifi on the RPi as an access point, so you could selectively monitor IoT devices you wonder about. (My Amazon Echo often triggers even when I don't use the "Echo" wake word, I have an Echo Gen 1 that if I say "backup" without the wake word, it will respond "nothing is currently playing". And it often lights up when I ask the google home a question. I'm close to disconnecting the Echo devices since Amazon's latest changes to prime music that "got lost in the shuffle". No more prime for me. Sorry for the tangent/rant about Amazon prime music.

  • @anthonynowlan9765
    @anthonynowlan9765 2 ปีที่แล้ว

    Perhaps show how to move that job into background etc. &

  • @grahamjkeddie
    @grahamjkeddie 2 ปีที่แล้ว

    Hey Chris,
    What is better - Dualcomm ETAP-2003 Tap or a switch with port mirroring? I have a Dualcomm ETAP-2003 (bought at work for my laptop) and wonder if I’ve made the wrong choice. Thanks

    • @bluejuice2503
      @bluejuice2503 2 ปีที่แล้ว +1

      Yeah you can Graham. The ETAP-2003 blocks traffic on the monitor port going back to the network (the ETAP-2003R model allows it) so if you have the ETAP-2003 model then you will need to enable the capture on the PI first and then connect it to the network you wish to capture from.

  • @bohuueeaa
    @bohuueeaa 2 ปีที่แล้ว +1

    Another good video from Chris Greer (:
    Addition to this great video, you can considerably increase the device's performance with pf_ring, which, I bet you already know about (:

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว

      Ooh nice, great tip yasin! Thank you.

  • @shruthesh
    @shruthesh 2 ปีที่แล้ว

    I watched the Video again to see how you got 2 Network interface on a regular Raspberri Pi. Felt stupid after I realized I completely forgot the Wireless interface.😅

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      It’s ok! I felt stupid the entire time I was setting the whole thing up.

  • @Cornelius-David
    @Cornelius-David 2 ปีที่แล้ว

    Hey Chris, you're a really good teacher, i love your content !
    I don't use youtube as much these days, but it would be awesome to see you on the Odysee video platform!
    Ask David Bombal, he posts regularly on it!
    Hope to see you there, and thanks for your awesome content :-)

  • @robertbatista50
    @robertbatista50 ปีที่แล้ว

    This may also be an option if you don’t take the SSD route… th-cam.com/video/LKDC-Wjukk0/w-d-xo.html

  • @Liqweed1337
    @Liqweed1337 หลายเดือนก่อน

    this video teached me nothing. it basically ended when the content began.

  • @faran_siddiqui-d3t
    @faran_siddiqui-d3t 2 ปีที่แล้ว

    Nice one man 🔥🔥

    • @ChrisGreer
      @ChrisGreer  2 ปีที่แล้ว +1

      Thanks! It's been fun to tinker with it. Now to get Suricata working...