68-5
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 68 Configuring Wireshark
Information about Wireshark
•
Wireshark cannot capture IPv6 packets if the capture point's class-map filter is attempting to match
one of the following:
–
Extension headers followed by Hop-by-hop header (as per CSCtt16385)
–
DSCP values (as per CSCtx75765)
Information about Wireshark
Note
Wireshark is only supported on Supervisor Engine 8-E, Supervisor Engine 7-E, Supervisor Engine 7L-E,
Catalyst 4500X-16, and Catalyst 4500X-32.
Note
Wireshark is supported on VSS and the functionality is the same as a standalone switch except for a few
configuration differences as detailed in the
“Configuring Wireshark on VSS” section on page 68-14
Wireshark is a packet analyzer program, formerly known as Ethereal, which supports multiple protocols
and presents information in a text-based user interface.
To understand what happens inside a network requires the ability to capture and analyze traffic. Prior to
Cisco IOS Release XE 3.3.0SG, the Catalyst 4500 series switch offered only two features to address this
need: SPAN and
debug platform packet
. Both are limited. SPAN is ideal for capturing packets, but can
only deliver them by forwarding them to some specified local or remote destination; it provides no local
display or analysis support. The
debug platform packet
command is specific to the Catalyst 4500 series
switch and only works on packets that stem from the software process-forwarding path. Although it has
limited local display capabilities, it has no analysis support.
So the need exists for a traffic capture and analysis mechanism that is applicable to both hardware and
software forwarded traffic and that provides strong packet capture, display and analysis support,
preferably using a well known interface.
Wireshark dumps packets to a file using a well known format called .pcap, and is applied or enabled on
individual interfaces. You specify an interface in EXEC mode along with the filter and other parameters.
The Wireshark application is applied only when you enter a
start
command and is removed only when
Wireshark stops capturing packets either automatically or manually.
Note
In Cisco IOS Release XE 3.3.0SG, global packet capture on Wireshark is not supported.
These sections describe some key concepts for Wireshark:
•
•
•
•
Input and Output Classification, page 68-7
•
•
Storing Captured Packets to Buffer in Memory, page 68-8
•
Decoding and Displaying Packets, page 68-9
•
Activating and Deactivating Wireshark Capture Points, page 68-10
Summary of Contents for Catalyst 4500 Series
Page 2: ......
Page 4: ......
Page 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...