Configuring an AP Packet Capture from the CLI

Using the CLI for collecting an AP packet capture is sometimes the only way to sample the AP traffic when the AP is not able to contact the controller.
Complete the following steps to collect an AP packet capture from the AP CLI:
  1. Enter the CLI of the AP. For additional instructions on this step, refer to Entering the AP CLI.
  2. Enter the command get wlanlist to find the WLAN number for which you want to capture the traffic. For example, in the CLI sample shown, wlan0 corresponds to the SSID "upstairs" in the 2.4 GHz radio (radioID 0) and wlan32 corresponds to the SSID "upstairs" in the 5 GHz radio (radioID 1).
    rkscli: get wlanlist
    name          status   type   wlanID   radioID  bssid             ssid
    --------------------------------------------------------------------------------------------------
    wlan0         up       AP     wlan0    0        fc:5c:45:40:44:d0 upstairs
    wlan1         down     AP     wlan1    0        00:00:00:00:00:00 Wireless2
    wlan2         down     AP     wlan2    0        00:00:00:00:00:00 Wireless3
    wlan3         down     AP     wlan3    0        00:00:00:00:00:00 Wireless4
    wlan4         down     AP     wlan4    0        00:00:00:00:00:00 Wireless5
    wlan5         down     AP     wlan5    0        00:00:00:00:00:00 Wireless6
    wlan6         down     AP     wlan6    0        00:00:00:00:00:00 Wireless7
    wlan7         down     AP     wlan7    0        00:00:00:00:00:00 Wireless8
    wlan8         down     AP     wlan8    0        00:00:00:00:00:00 Wireless 8
    wlan9         down     AP     wlan9    0        00:00:00:00:00:00 Wireless 9
    wlan10        down     AP     wlan10   0        00:00:00:00:00:00 Wireless 10
    wlan11        down     AP     wlan11   0        00:00:00:00:00:00 Wireless 11
    wlan12        down     AP     wlan12   0        00:00:00:00:00:00 Wireless 12
    wlan13        down     AP     wlan13   0        00:00:00:00:00:00 Wireless 13
    meshu         down     STA    wlan31   0        00:00:00:00:00:00 ruckus_cluster
    wlan100       down     MON    wlan100  0        00:00:00:00:00:00
    recovery-ssid down     AP     wlan102  0        00:00:00:00:00:00 Recover.Me-0044D0
    wlan32        up       AP     wlan32   1        fc:5c:45:80:44:d0 upstairs
    wlan33        down     AP     wlan33   1        00:00:00:00:00:00 Wireless33
    wlan34        down     AP     wlan34   1        00:00:00:00:00:00 Wireless11
    wlan35        down     AP     wlan35   1        00:00:00:00:00:00 Wireless12
    wlan36        down     AP     wlan36   1        00:00:00:00:00:00 Wireless13
    wlan37        down     AP     wlan37   1        00:00:00:00:00:00 Wireless14
    wlan38        down     AP     wlan38   1        00:00:00:00:00:00 Wireless15
    wlan39        down     AP     wlan39   1        00:00:00:00:00:00 Wireless16
    wlan40        down     AP     wlan40   1        00:00:00:00:00:00 Wireless 40
    wlan41        down     AP     wlan41   1        00:00:00:00:00:00 Wireless 41
    wlan42        down     AP     wlan42   1        00:00:00:00:00:00 Wireless 42
    wlan43        down     AP     wlan43   1        00:00:00:00:00:00 Wireless 43
    wlan44        down     AP     wlan44   1        00:00:00:00:00:00 Wireless 44
    meshd         down     AP     wlan62   1        00:00:00:00:00:00 mesh-EfXEQi0o
    meshu         down     STA    wlan63   1        00:00:00:00:00:00 mesh-EfXEQi0o
    wlan101       up       MON    wlan101  1        00:00:00:00:00:00
    OK
    rkscli:
    
  3. Enter the command get client-info wlan_number to find the client information in the AP including the client MAC address and the WLAN to which it is connecting. For example, in the CLI sample shown, wlan32 has one client connected, the Android client with MAC address ee:b0:fa:69:13:9f and IP address 192.168.100.9.
    rkscli: get client-info wlan32
    ee:b0:fa:69:13:9f {
        Allow                   : Y
        Device Info             : { Smartphone, Android, Generic Smartphone/Android 10.0.0 } [HTTP]
        Hostname                : Galaxy-S23
        Forwarding Policy       : 4(LBOAP)
        VLAN ID                 : 1
        IP Address              : 192.168.100.9 (H)
        IPv6 Address            :
        DHCP Lease Time         : 2837
        DHCP XID                : 0x59da85f8
        Packet Drop (Force DHCP): 0
        DHCP ACK Packets        : 6
        Life Time               : 300
        FIREWALL ID             : 1
        CI Unicast Filter       : Disabled
        CI Multicast Filter     : Disabled
        Antispoof arpreq_count  : 0
        Antispoof dhcpreq_count : 0
        CUI                     :
        DHCP Pool Name          :
        NAT Pool Name           :
        Session Duration        : 9789
        Station Type            : Wireless
        Roam state              : New connection
        Auth Type               : Standard
        Auth Method             : Open
        RL UPlink               : 0
        RL Downlink             : 0
    }
    --------
    summary:
    Total Clients: 1
    
  4. Enter the command set capture wlan_number stream to start the traffic streaming from the AP.
    rkscli: set capture wlan32 stream
    rccd pkt mode file /tmp/rccd_pcap_status is not present
    Packet capture on wlan101
    disabling the HCCD packet captures
    Connection established.
    OK
    
  5. Start Wireshark and configure the remote interface to collect in real-time the traffic the AP is streaming. For instructions to configure a remote interface, refer to Configuring a Remote Interface in Wireshark.
  6. Enter the command get capture wlan_number state to verify the state if the packet capture.
  7. Enter the command set capture wlan_number idle to stop the traffic streaming from the AP.
For guidance about analyzing packet captures in Wireshark, refer to Troubleshooting with AP Packet Captures.