Therefore, Ruckus recommends performing packet capture only on the 2.4 GHz radio
of a Mesh AP. Root APs (and eMAPs) do not have this limitation and packet capture
can be performed on either radio.
The local capture mode stores packet data from a single capture session in two files
using a “ping-pong” method. Due to memory limitations, the capture files are cleared
after they are retrieved by the Save command and before each new capture session,
and they are not retained on the AP between reboots.
In streaming capture mode, packet data from the 2.4 GHz and 5 GHz radios are available
simultaneously on AP interfaces wifi0 and wifi1, respectively. The streams can be
accessed using Wireshark’s remote interface capture option. The Windows version of
Wireshark (e.g., v1.2.10) supports this option. Linux versions may not.
Both output modes support packet filtering. In local capture mode, the AP accepts a
packet filter expression and applies it before storing the file. In streaming mode, Wireshark
accepts a capture filter expression and sends it to a daemon running on the AP, which
applies it before streaming. Both modes allow compound filter expressions conforming
to the pcap-filter syntax, which is described at filter/.
Local Capture
To capture packets to a local file for external analysis:
1.
Choose 2.4 GHz radio (you can only capture packets on one radio at a time).
2.
Select one or more APs from the list and click
Add to Capture APs
. The APs you
selected are moved from the Currently Managed APs table on the left side to the
new Capture APs table on the right.
3.
Select
Local Mode
to save the packet capture to a local file.
4.
Click
Start
to begin capturing packets. Click
Stop
to end the capture, and click
Save
to save the packet capture to a local file.
5.
Extract the pcap file(s) from the pcap.zip file and open in Wireshark or other packet
analyzer.
Streaming Mode
To view streaming packets in real time using Wireshark’s remote capture:
1.
Choose 2.4 GHz or 5 GHz radio.
2.
Select the AP you want to view and click
Add to Capture APs
.
3.
Select Streaming Mode and click
Start
.
4.
Launch Wireshark.
5.
Go to
Capture Options
.
6.
Under
Capture: Interface
, select
Remote
. A
Remote Interface
dialog appears.
7.
In Host, enter the IP address of the AP you want to view. Leave the
Port
field empty
OK
.
349
Ruckus Wireless ZoneDirector™ Release 10.0 User Guide
Troubleshooting
Packet Capture and Analysis