68-29
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 68 Configuring Wireshark
Usage Examples for Wireshark
Protocol: any
File Details:
Associated file name: bootflash:mycap.pcap
Buffer Details:
Buffer Type: LINEAR (default)
Limit Details:
Number of Packets to capture: 100
Packet Capture duration: 60
Step 3
Launch packet capture by entering:
Switch#
monitor capture mycap start
Let the capture operation stop automatically after the time has elapsed or the packet count has been met.
The
mycap.pcap
file now contains the captured packets.
Step 4
Display the packets by entering:
Switch#
show monitor capture file bootflash:mycap.pcap
0.000000 10.1.1.30 -> 20.1.1.2 UDP Source port: 20001 Destination port: 20002
1.000000 10.1.1.31 -> 20.1.1.2 UDP Source port: 20001 Destination port: 20002
2.000000 10.1.1.32 -> 20.1.1.2 UDP Source port: 20001 Destination port: 20002
3.000000 10.1.1.33 -> 20.1.1.2 UDP Source port: 20001 Destination port: 20002
4.000000 10.1.1.34 -> 20.1.1.2 UDP Source port: 20001 Destination port: 20002
5.000000 10.1.1.35 -> 20.1.1.2 UDP Source port: 20001 Destination port: 20002
6.000000 10.1.1.36 -> 20.1.1.2 UDP Source port: 20001 Destination port: 20002
7.000000 10.1.1.37 -> 20.1.1.2 UDP Source port: 20001 Destination port: 20002
8.000000 10.1.1.38 -> 20.1.1.2 UDP Source port: 20001 Destination port: 20002
9.000000 10.1.1.39 -> 20.1.1.2 UDP Source port: 20001 Destination port: 20002
Step 5
Delete the capture point by entering:
Switch#
no monitor capture mycap
Example: Simple Capture and Store in Lock-step with High-speed Mode
This example shows how to capture live traffic and store the packets in lock-step with high-speed mode
to achieve high capture rate.
Note
The capture rate might be slow for the first 15 seconds. If possible and necessary, start the traffic 15
seconds after the capture session starts.
Step 1
Define a capture point to match on the relevant traffic and associate it to a file by entering:
Switch#
monitor capture mycap interface gi 3/1 in match ipv4 any any
Switch#
monitor capture mycap limit duration 60 packets 100
Switch#
monitor cap mycap file location bootflash:mycap.pcap buffer-size 90
Step 2
Confirm that the capture point has been correctly defined by entering:
Switch#
show monitor capture mycap parameter
monitor capture mycap interface GigabitEthernet3/1 in
monitor capture mycap match ipv4 any any
monitor capture mycap file location bootflash:mycap.pcap buffer-size 90
monitor capture mycap limit packets 100000 duration 60
Switch#
show monitor capture mycap
Target Type:
Interface: GigabitEthernet3/1, Direction: in
Summary of Contents for Catalyst 4500 Series
Page 2: ......
Page 4: ......
Page 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...