Packet capture
Capture the traffic on one link while the environment runs, then download the pcap.
Links between devices are separate segments (shared segments are supported too). That is what lets ONEP capture the traffic on exactly one link, while the rest of the environment keeps running, and hand you a standard pcap file to open in Wireshark or any other analyzer. Packet capture and pcap download are available on every edition.
Capture on a link#
- Power on the link's devicesA capture needs an active link. ONEP refuses to start one on a link that is not up, so power on the environment, or both devices on the link, first.
- Open the capture dialogRight-click a device and choose More > Diagnostics > Packet Capture. Or select a link on the canvas and choose Capture on this link in the bar above it. Either way ONEP opens Packet Capture for a device and lists that device's links, one row per link, named after the two devices it joins. The button on a selected link opens the dialog for the device at one end of it, so start the row you want.
- Start the captureChoose Start on the row. A running capture shows a pulsing dot and the size captured so far, in KB. It covers both directions of the link and stops by itself after five minutes.
- Make the trafficyou want to see: a ping, a login or a test attack.
- Stop the capturewith the stop button on the row when you have what you need.
- Download the pcapwith the download button that appears on the row once the capture has stopped and holds data. The file is named
capture_followed by a short link id and.pcap. Open it in your own analyzer.
Capture report#
Once a capture has stopped, a Report button next to the download button builds an analysis report from it and downloads it as a PDF when it is ready. The report contains the protocol hierarchy, top talkers, conversations, the first frames, a decoded narrative of the traffic and suggested analyst filters. The report depends on your edition; where it is locked, the row says so. See Limits per edition.
Who can capture#
Capturing needs the packet capture permission of your role. Without it the Packet Capture row is not shown in the device menu, Capture on this link is greyed out, and the dialog says "Your role does not allow packet capture." See Users and roles.
Good to know#
- Capture works on links, not devices. To see all traffic of a device with several links, capture on each of its links; each row in the dialog runs its own capture.
- The download and the report are available only after the capture has stopped.
- Vendor switch images can also mirror traffic themselves with their own mirror or SPAN sessions, configured from their console.