Korenix Technology Co., Ltd.
Industrial
Layer 3 Managed Ethernet Switch
_____________________________________________________________________________
Industrial Layer 3 Managed Ethernet SwitchUser Manual
Page: 527/1568
6.17.18.2.3 Capture packet to file, remote or line
Use this command to configure packet capture options. This command is persistent across a reboot
cycle.
Syntax
capture {file | remote | line}
file
–
In the capture file mode, the captured packets are stored in a file on Flash. The maximum file
size defaults to 512KB. The switch can transfer the file to a TFTP server via TFTP, FTP via CLI. The
file is formatted in pcap format, is name cpu-pkt-capture.pcap, and can be examined using network
analyzer tools such as W ireshark or Ethereal. Starting a file capture automatically terminates any
remote capture sessions and line captureing. After the packet capture is activated, the capture
proceeds until the capture file reaches its maimum size, or until the capture is stopped manually
using CLI command
„capture stop“.
Remote
–
In the remote capture mode, the captured packets are redirected in real time to an
external PC running the wireshark tool for Microsoft W indows. A packet capture server runs on the
switch side and sends the captured packets via a TCP connection to the W ireshark tool. The remote
capture can be enabled or disable using the CLI. There should be a W indows PC with the W ireshark
tool to display the captured file. When using the remote capture mode, the switch does not sotre any
captured data locally on its file system.
You can configure the IP port number for connecting Wireshark to the switch. The default port
number is 2002. If a firewall is installed between the W ireshark PC and the switch, then these ports
must be allowed to pass through the firewall.
If the client successfully connects to the switch, the CPU packets are sent to the client PC, then
Wireshark receives the packets and displays them. This continues until the session is terminated by
either end.
l
ine
–
In the capture line mode, the captured packets are saved into the RAM and can be displayed
on the CLI. Starting a line capture automatically terminates any remote capture dession and
capturing into a file. There is a maximum 128 packets of maximum 128 btes that can be captured
and displayed in Line mode.
Default Setting
Remote
Command Mode
Global Config