Hi, Fadi, just to be sure. These two links are also yours, right?
about sniffing,
So. yes, to be able to capture traffic you will need a device with mirror capabilities.
Here you have a block diagram of what your network should look like.
Some
times wifi router has monitoring capabilities, so you would need the two boxes. just one will work. But this usually doesn't happen.
Another
point is your internet router using a wifi system. this is my scenario, so I did buy a wifi router and an extra switch to have a
better and easier way to monitor my network.
Most the important thing here is the sniffing workstation, the one that will run
Suricata/Zeek/tcpdump/wireshark, this should be connected to the network with two interfaces. one with IP to be able to manage it and the second interface without IP and wired to the monitor port on your switch.
Happy to have a deeper discussion
about this, please as requested in the other thread, share your network
so we can share with you more options.
Hope this helps,
Thanks so much