thehorse13 is right, just try it on your gateway and you will catch more traffic than you know what to do with. Very system intensive if you are realtime.
You do need to take advantage of the port mirroring feature though. Plus if you are on a gateway it matters not that you have 60000 switches below, all that traffic has to hit the gateway. Well all outbound traffic. And if that is the case then setup your 'sniffer' consoles at the 'smart' switches (mirror that too).
I know this works fairly well because I have implemented it as a consultant. Not the whole sight picture in itself but a large portion. Not sure about the team of people you will need to 'sift' through the packets, but then again, if you set up the ethereal filters to suit your needs you shouldn't have to.




Reply With Quote