< <
Port-Mirroring / Span Port / Monitor Port with iptables on NETGEAR WGR614L

I have a NETGEAR WGR614L and I needed to attach a tcp monitor pc (tcpdump) to one of its LAN ports. The fact the the router is a switch makes that not so trivial a task. 

The switch only forwards packets to the port where the destinaion MAC address is known.  As such, each connected network device only receives the packets which are destined for that specific device.

Expensive switches provide a functionality which is called “Port-Mirroring," “Span Port,” or “Monitor Port."  This feature copies all packets from another port to that monitor port.  Sadly, our WGR614L doesn't have that functionality built-in.

After a day of forum searching and Googling, all I could find was the question on how to do this and the answer that it’s impossible.

However, I asked the question in this forum and received a brilliant answer (thanks again to ciscostu).

The solution lies in iptables!

There is an experimental target (ROUTE) which offers an option (--tee) that behaves like the good old linux “tee” command.  It copies a packet to a target ip address and then goes on with the normal behaviour (routing it to it’s normal target.)

So, how are we going to use this for our port-mirroring?

Imagine that our router has the ip address, and our monitor pc has the ip address Then the following two lines will do the trick:

iptables -A PREROUTING -t mangle -j ROUTE --gw --tee

iptables -A POSTROUTING -t mangle -j ROUTE --gw --tee

This will send a copy of all packets to the monitor pc with the ip

On the monitor, we simply start tcpdump with our desired options and we can monitor all traffic…

In my example, I’m interested in all traffic which has to do with the ip so I call:

tcpdump (…) host

Where (…) are some more options for logging andother things.

I hope this little guide helps many many people and i’d appreciate some comments :)

Gr33tz Goddchen

Tags : ip tablesmonitor portport mirroringwgr614l

Discussion:

View unverified member's comment - posted by Etherninja

September 23, 2009 1:33 PM

Thanks mate.. it works well on my wrt54gl router with DDWRT v23SP2. I've got my router logging to a debian machine with ntop running on a VM.. lovely. In fact it is more accurate for bandwidth analysis than enabling the default rflow (netflow) Needless to say I ran the commands from the bash command line.. once again.. thank you - very useful post.

October 24, 2009 5:36 PM

That's great - now how to turn it off without a router reboot?

March 21, 2011 6:25 AM

is it possible to specify only for one interface of the router???

November 24, 2012 6:17 AM

Oh, very helpful, even several years later! Thanks for sharing.

March 9, 2015 5:45 PM

the gw command does not work.
iptables v1.4.12: unknown option "--gw"
Try `iptables -h' or 'iptables --help' for more information.

Discussion:

