•
Local Capture Method
— Captured packets are stored in a file on the WAP device. The WAP device
can transfer the file to a TFTP server. The file is formatted in pcap format and can be examined using
Wireshark. You can choose
Save File on this Device
to select the local capture method.
•
Remote Capture Method
— Captured packets are redirected in real time to an external computer running
Wireshark. You can choose
Stream to a Remote Host
to select the remote capture method.
Captured packets could be redirected in real time to CloudShark, a web-based packet decoder and analyzer
site. It is similar to Wireshark UI for packet analysis. You can choose
Stream to CloudShark
to select
the remote capture method.
The WAP device can capture these types of packets:
• 802.11 packets received and transmitted on the radio interfaces. Packets captured on the radio interfaces
include the 802.11 header.
• 802.3 packets received and transmitted on the Ethernet interface.
• 802.3 packets received and transmitted on the internal logical interfaces, such as VAPs and WDS
interfaces.
Use the Packet Capture page to configure the parameters of the packet capture, start a local or remote packet
capture, view the current packet capture status, and download a packet capture file.
Local Packet Capture
To initiate a local packet capture:
Step 1
Select
Troubleshoot > Packet Capture
.
Step 2
Ensure that
Save File on this Device
is selected for the Packet Capture Method.
Step 3
Configure these parameters:
•
Interface
— Enter a capture interface type for packet capture:
•
Ethernet
— 802.3 traffic on the Ethernet port.
•
Radio 1 (5 GHz) / Radio 2 (2.4 GHz)
— 802.11 traffic on the radio interface.
•
Duration
— Enter the time duration in seconds for the capture. The range is from 10 to 3600. The default is 60.
•
Max File Size
— Enter the maximum allowed size for the capture file in kilobytes (KB). The range is from 64 to
4096. The default is 1024.
Step 4
There are two modes for packet capture.
•
All Wireless Traffic
— Captures all wireless packets.
•
Traffic to/from this AP
— Captures the packets sent from the AP or received by the AP.
Step 5
Click
Enable Filters
. There are three checkboxes available (
Ignore Beacons, Filter on Client, Filter on SSID
).
•
Ignore Beacons
— Enables or disables the capturing of 802.11 beacons detected or transmitted by the radio.
Cisco WAP581 Wireless-AC/N Dual Radio Access Point with 2.5GbE LAN Administration Guide
114
Troubleshoot
Local Packet Capture