We have a vendor managed NAT Router/Authentication device for free WiFi attached to eth1 on our Astaro ASG-120. I have a packet rule setup that blocks all traffic from this interface to all our internal network segments (eth0.1, eth0.2, eth0.3) at the top of my packet rules list. I am periodically seeing IPS port scanning activity coming from the ip address we have assigned to the free WiFi NAT router with attempted scanning going on to external public internet addresses. Is there a way capture all network traffic from the wifi hotspot network to a computer running wireshark on another network segment on demand? Currently the WiFi Nat device connects straight to the ASG, not through my layer 3 switch otherwise I could setup a TAP on the port and capture that way.
I would like to capture the traffic to see exactly what kind of activity is being attempted when this is occurring so we can decides to take action if neccessary.
This thread was automatically locked due to age.