•
All traffic to and from a specific client:
wlan.addr == 00:00:e8:4e:5f:8e
In remote capture mode, traffic is sent to the computer running Wireshark through one of the network interfaces. Depending
on the location of the Wireshark tool, the traffic can be sent on an Ethernet interface or one of the radios. To avoid a
traffic flood caused by tracing the packets, the WAP device automatically installs a capture filter to filter out all packets
destined to the Wireshark application. For example, if the Wireshark IP port is configured to be 58000, then this capture
filter is automatically installed on the WAP device:
not port range 58000-58004
Due to performance and security issues, the packet capture mode is not saved in NVRAM on the WAP device. If the
WAP device resets, the capture mode is disabled and then you must enable it again to resume capturing traffic. Packet
capture parameters (other than the mode) are saved in NVRAM.
Enabling the packet capture feature can create a security issue: Unauthorized clients may be able to connect to the WAP
device and trace user data. The performance of the WAP device also is negatively impacted during packet capture, and
this impact continues to a lesser extent even when there is no active Wireshark session. To minimize the performance
impact on the WAP device during traffic capture, install capture filters to limit which traffic is sent to the Wireshark
tool. When capturing 802.11 traffic, a large portion of the captured frames tend to be beacons (typically sent every 100
ms by all access points). Although Wireshark supports a display filter for beacon frames, it does not support a capture
filter to prevent the WAP device from forwarding the captured beacon packets to the Wireshark tool. To reduce the
performance impact of capturing the 802.11 beacons, disable the capture beacons mode.
Packet Capture File Download
You can download a capture file by TFTP to a configured TFTP server, or by HTTP/HTTPS to a computer.
A capture is automatically stopped when the capture file download command is triggered.
Because the capture file is located in the RAM file system, it disappears if the WAP device is reset.
To download a packet capture file using TFTP:
Step 1
Click
Download to TFTP Server
.
Step 2
Specify a TFTP Server IPv4 Address in the field provided.
Step 3
Enter the TFTP Server Filename to download if different from the default. By default, the captured packets are stored
in the folder file /tmp/apcapture.pcap on the WAP device.
Step 4
Click
Download
.
Cisco WAP125 Wireless-AC/N Dual Band Desktop Access Point with PoE
103
Troubleshoot
Packet Capture File Download