D-Link DWL-3600AP Users Manual - Page 125

Packet File Capture, Remote Packet Capture, Refresh, Capture Interface, Capture Duration

Page 125 highlights

Unified Access Point Administrator's Guide Packet Capture Configuration and Settings Packet File Capture In Packet File Capture mode the AP stores captured packets in the RAM file system. Upon activation, the packet capture proceeds until one of the following occurs: • The capture time reaches configured duration • The capture file reaches its maximum size • The administrator stops the capture During the capture, you can monitor the capture status, elapsed capture time, and the current capture file size. This information can be updated, while the capture is in progress, by clicking Refresh. Table 49 describes the fields to configure the packet capture status. Field Capture Interface Capture Duration Max Capture File Size Table 49: Packet File Capture Description Select an AP Capture Interface name from the drop‐down menu. AP capture interface names are eligible for packet capture are: • brtrunk ‐ Linux bridge interface in the AP • eth0 ‐ 802.3 traffic on the Ethernet port. • wlan0 ‐ VAP0 traffic on radio 1. • wlan1 ‐ VAP0 traffic on radio 2. • radio1 ‐ 802.11 traffic on radio 1. • radio2 ‐ 802.11 traffic on radio 2. Note: The DWL‐3600AP has only one radio. The available options on the DWL‐3600AP do not include wlan0 or radio1. Specify the time duration in seconds for the capture (range 10 to 3600). Specify the maximum allowed size for the capture file in KB (range 64 to 4096). Remote Packet Capture Remote Packet Capture allows you to specify a remote port as the destination for packet captures. This feature works in conjunction with the Wireshark network analyzer tool for Windows. A packet capture server runs on the AP and sends the captured packets via a TCP connection to the Wireshark tool. A Windows PC running the Wireshark tool allows you to display, log, and analyze captured traffic. When the remote capture mode is in use, the AP doesn't store any captured data locally in its file system. Your can trace up to five interfaces on the AP at the same time. However, you must start a separate Wireshark session for each interface. You can configure the IP port number used for connecting Wireshark to the AP. The default port number is 2002. The system uses 5 consecutive port numbers starting with the configured port for the packet capture sessions. If a firewall is installed between the Wireshark PC and the AP, these ports must be allowed to pass through the firewall. The firewall must also be configured to allow the Wireshark PC to initiate TCP connection to the AP. D-Link November 2011 Unified Access Point Administrator's Guide Page 125

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183

Packet Capture Configuration and Settings
D-Link
Unified Access Point Administrator’s Guide
November 2011
Page 125
Unified Access Point Administrator’s Guide
Packet File Capture
In Packet File Capture mode the AP stores captured packets in the RAM file system.
Upon activation, the packet capture proceeds until one of the following occurs:
The capture time reaches configured duration
The capture file reaches its maximum size
The administrator stops the capture
During the capture, you can monitor the capture status, elapsed capture time, and the current capture file size.
This information can be updated, while the capture is in progress, by clicking
Refresh
.
Table 49
describes the fields to configure the packet capture status.
Remote Packet Capture
Remote Packet Capture allows you to specify a remote port as the destination for packet captures. This feature
works in conjunction with the Wireshark network analyzer tool for Windows. A packet capture server runs on
the AP and sends the captured packets via a TCP connection to the Wireshark tool.
A Windows PC running the Wireshark tool allows you to display, log, and analyze captured traffic.
When the remote capture mode is in use, the AP doesn't store any captured data locally in its file system.
Your can trace up to five interfaces on the AP at the same time. However, you must start a separate Wireshark
session for each interface. You can configure the IP port number used for connecting Wireshark to the AP. The
default port number is 2002. The system uses 5 consecutive port numbers starting with the configured port for
the packet capture sessions.
If a firewall is installed between the Wireshark PC and the AP, these ports must be allowed to pass through the
firewall. The firewall must also be configured to allow the Wireshark PC to initiate TCP connection to the AP.
Table 49: Packet File Capture
Field
Description
Capture Interface
Select an AP
Capture Interface
name from the drop
down menu. AP capture
interface names are eligible for packet capture are:
brtrunk
Linux bridge interface in the AP
eth0
802.3 traffic on the Ethernet port.
wlan0
VAP0 traffic on radio 1.
wlan1
VAP0 traffic on radio 2.
radio1
802.11 traffic on radio 1.
radio2
802.11 traffic on radio 2.
Note:
The DWL
3600AP has only one radio. The available options on the
DWL
3600AP do not include wlan0 or radio1.
Capture Duration
Specify the time duration in seconds for the capture (range 10 to 3600).
Max Capture File Size
Specify the maximum allowed size for the capture file in KB (range 64 to 4096).