[geeks] tiny network tap

Charles Shannon Hendrix shannon at widomaker.com
Sat Sep 17 05:35:50 CDT 2016


New project: tiny network tap

Lately, I have been downsizing my computer gear. I built an Unraid and bought
a QNAP server, and pretty much everything now runs as containers and VMs on
those.

I want to build a network tap to monitor my Internet connection, something
where I can do packet forensics, packet data storage, network top type
monitors, and so on. Basically snoop all of my traffic.

The primary purpose here is learning, and a couple of data analysis projects I
have in mind. One thing Ibll use it for is a way to create very large and
plausible data sets for my classes in EDA and R.

Also, its cool.

So, I have some goals:

	- intercept EVERYTHING in and out
	- no appreciable speed loss
	- as little added latency as possible
	- network tap machine: I want it as small, low power, and cool as possible
	- ability to spin a RAID for data storage at decent speed

This will likely go between my Netgear router and my cable modem, and needs to
be able to work with a FIOS setup since Ibm likely to be converting to that
in a year or so.

I have my own ideas for how to build a machine like this, but would love to
hear from you guys as well, especially if you have already done this.

I even toyed with the idea of actually just building a fast but small router
that would happen to have this function, and would entertain ideas along that
line as well.

Ibm not sure when Ibll do it, but I do plan to eventually split my network
up into subnets, mainly to learn but also so isolate some projects I am
working on.


More information about the geeks mailing list