Administration
Packet Capture
Cisco Small Business WAP371 Wireless Access Point Administration Guide
46
3
•
Data frames only:
wlan.fc.type == 2
•
Traffic on a specific BSSID:
wlan.bssid == 00:02:bc:00:17:d0
•
All traffic to and from a specific client:
wlan.addr == 00:00:e8:4e:5f:8e
In remote capture mode, traffic is sent to the computer running Wireshark through one of the
network interfaces. Depending on the location of the Wireshark tool, the traffic can be sent on
an Ethernet interface or one of the radios. To avoid a traffic flood caused by tracing the
packets, the WAP device automatically installs a capture filter to filter out all packets destined
to the Wireshark application. For example, if the Wireshark IP port is configured to be 58000,
then this capture filter is automatically installed on the WAP device:
not portrange 58000-58004
Due to performance and security issues, the packet capture mode is not saved in NVRAM on
the WAP device; if the WAP device resets, the capture mode is disabled and then you must
reenable it to resume capturing traffic. Packet capture parameters (other than mode) are saved
in NVRAM.
Enabling the packet capture feature can create a security issue: Unauthorized clients may be
able to connect to the WAP device and trace user data. The performance of the WAP device
also is negatively impacted during packet capture, and this impact continues to a lesser extent
even when there is no active Wireshark session. To minimize the performance impact on the
WAP device during traffic capture, install capture filters to limit which traffic is sent to the
Wireshark tool. When capturing 802.11 traffic, a large portion of the captured frames tends to
be beacons (typically sent every 100 ms by all APs). Although Wireshark supports a display
filter for beacon frames, it does not support a capture filter to prevent the WAP device from
forwarding captured beacon packets to the Wireshark tool. To reduce the performance impact
of capturing the 802.11 beacons, disable the capture beacons mode.
Packet Capture File Download
You can download a capture file by TFTP to a configured TFTP server, or by HTTP(S) to a
computer. The capture file is located in the RAM file system, it disappears if the WAP device
is reset.
To download a packet capture file using TFTP:
Содержание WAP371
Страница 13: ...Getting Started Window Navigation Cisco Small Business WAP371 Wireless Access Point Administration Guide 9 1 ...
Страница 52: ...Administration Support Information Cisco Small Business WAP371 Wireless Access Point Administration Guide 48 3 ...
Страница 60: ...LAN LLDP Cisco Small Business WAP371 Wireless Access Point Administration Guide 56 4 ...
Страница 99: ...Wireless Quality of Service Cisco Small Business WAP371 Wireless Access Point Administration Guide 95 5 ...
Страница 132: ...Simple Network Management Protocol Targets Cisco Small Business WAP371 Wireless Access Point Administration Guide 128 8 ...
Страница 161: ...Single Point Setup Wireless Neighborhood Cisco Small Business WAP371 Wireless Access Point Administration Guide 157 10 ...