I have a dsl modem that is plugged into a firewall/VPN box. I wanted to monitor what goes on between the ISP gateway and my firewall so I got a simple hub and inserted it between DSL modem and firewall.
I then configured by laptop with an IP address on the same subnet as my external ip (this may be optional if I remember correctly a card placed in promiscuous mode should get all the traffic anyway)
I then plugged the laptop into the hub and got Ethereal packet sniffer running on the laptop
Here's my problem. I am not able to see all of the traffic!
I see mostly ARP messages and occasionally TCP and UDP packets between hosts that are outside of my LAN (small surprise here)
But I do not see my attempts to access internet which successfully traverse that same firewall and come back with data through that same hub. I find this alarmingly weird.
Does anybody know if there is a reason for this ? Really appreciate help on this one.
-amerphy