Ethernet Tap

Ethernet Tap

The Ethernet Tap plugin should be used together with an Ethernet Tap device from Tibbo Technology Inc.

The hardware sniffer is based on MAX10 FPGA. The firmware on FPGA reads Ethernet packets from the two RJ45 ports, passes all the traffic through with a delay equal to about 5.2uS, and sends all packets to IO Ninja over a USB link in real time.

Ethernet Tap connection

Usage

Select an Ethernet Tap device in the Tap dropdown, hit the Capture button, and you shall see all the packets on both RJ45 ports in real time. You can filter the packet list in the log at any time by entering a so-called pcap-filter in the Filter edit (click Apply to rebuild the log using the new filter). A complete reference on the filter syntax can be found at the official tcpdump manpage.

The Ethernet Tap plugin makes use of the new detail pane introduced in IO Ninja v3.12.0. The master log contains a list of packets (as well as other informational, warning, and error messages), a human-readable digest for each packet, and a two-liner payload preview. To inspect the raw contents of any packet, click on it in the master log, and the packet will be displayed in details in the pane below.

The color highlighting in the details pane helps you to visually distinguish between multiple protocols involved in the protocol stack for each particular packet. Clicking on any field automatically selects the corresponding region in the raw hex dump of a packet, thus making it easier for you to investigate the gory low-level details when you need to.

You can also export a log in the .pcap format for further analysis in other packet analyzers (such as Wireshark).

Gallery