And put the NIC in Promiscuous mode.

I have a machine setup for that.

It has 2 NICs in it. One for connecting to the LAN for regular stuff. Another for plugging into a hub, in listen only promicuous mode.

I bought on of the cheapest 10/100 hubs I could find. I leave daisy chained from the private interface of my Linux firewall.

That is the one thing I wish my unmanaged switches had, a mirroring port. (hmmm, an I idea.)

Basically, you could also use a real firewall, rather than a PIX. I hates them, I do, for reasons you are acutely aware of now.


Redo: Actually, now that I remember I am using a new setup, I actually just use the firewall itself to find the culprits. It is easy, run ethereal on the private interface for internal problems... run it on the public interface for external problems.