Packet Sniffing with an ASUS RT-N12

Status
Not open for further replies.

DBB2010

In Runtime
Messages
162
Location
Katy, TX
The ASUS RT-N12 wireless router has the ability to act as a wired/wireless router, repeater and access point with the original firmware installed. It seems to be a very solid router for the price and I have a very basic but specific task that I need it to perform and I don't know if it can be done with the original firmware or another version from a third party source like DDWRT.

In an environment where there are wired and wireless connections, I need to monitor wireless connections only, our wired connections are trusted. I would like to set up the current router to accept wired connections and then limit wireless connectivity to allow only the MAC of the new ASUS router. Then, I want to configure the ASUS router to act as a repeater for wireless connectivity, keeping the network fully functional but funneling all wireless traffic through the ASUS router and showing no change in accessibility/SSID/passphrase/etc. Finally [this is where I questioned my planning], I'd like to add a wired connection between the ASUS router and our server to monitor all traffic transmitted wirelessly and store it on the server for later inspection.

My question is, for anyone with experience with the RT-N12 or a similar situation,
1.) Can I monitor the wireless traffic of the router through a wired port?
2.) Do the wired ports act as a hub when in repeater mode?
3.) If they do act as a hub, do they only repeat traffic from/to other wired ports or does it repeat each frame it receives?
4.) Even if a function like this is not natively supported, might it be something possible with a more robust firmware?
5.) Any suggestions/alternatives that are relatively close to the cost [$30 router] and purpose of this project?

Thanks for any and all help, I know this is simple to some but I could really use a little input. I hope this isn't mistaken as illegal [like the forum rules describe], the only reason I have access to configure what is necessary to make this possible is because this is my network.
 
to monitor network going along a particular path you would need whats called a network sensor, these work through port mirroring, which you would probably need a layer 3 switch to do, so i do not think you can sniff packets through a wired connection on a router, you'd need an IDS sensor placed on specific host machines along the network but that wouldnt be what you want really.
(note: network sensors are generally for malicious attempts but in a bypass mode it can just be used to monitor connections)

i'm not to sure, i think alot of other network mapping utilities are mostly non-routable. though sniffing software like wireshark you might want to give a try

also if you were to set up ports on a router as a dedicated hub or repeater well... firstly, i dont have much routing experieng so im not sure if you could do that, but changing the ports to repeat wouldnt allow them to be routed as these are two different devices that work on 2 different layers of the OSI model.
unless you just wanted a repeater :p im not sure how that would affect the wireless in any case. sorry
 
The thing is, with all the features this thing has, there has to be a way to take the data routed by/through the wireless interface and mirror/span/pass it to a physical port. You can set up to 4 SSIDs and create VLANs between them and the switch ports. Even if it's not a feature intended for the router, I think it's possible to set up. I could be totally wrong but I intend to either make it work or be certain that it can't before I'm satisfied. I'll bring it to my Cisco Academy teacher and see if he has any ideas. The right combination of MAC spoofing, VLANs, Multiple SSIDs, Router/AP/Repeater modes built into the router and all the other features of DD-WRT's firmware should be enough to adapt such a simple function. I'll be sure to post what I find. Thanks guys!
 
Status
Not open for further replies.
Back
Top Bottom