Configuring an AP Packet Capture from the GUI
Using the GUI for collecting an AP packet
capture is a simple way for sampling the AP traffic either in the wireless or wired
interfaces. The controller GUI provides options to select traffic type, and filter
through
the client MAC address, as well as options for streaming the traffic to a collecting
computer for real-time analysis or save it in a file for later analysis.
Follow these steps to initiate an AP packet capture from the GUI:
- In the main menu, select . In the Access Points page, select an AP.
- Click
More and select
Packet Capture.
The Packet Capture dialog box appears.
- Select the Capture
Mode.
- Stream to
Wireshark. In this mode the AP sends a copy of the selected
traffic to the destination computer through which this traffic can be
received and analyzed in real-time. This traffic stream stops when you click
Stop.
Note: When streaming to Wireshark, you must first configure a remote interface in Wireshark to capture this traffic. For instructions to configure a remote interface, refer to Configuring a Remote Interface in Wireshark.
- Enter the Wireshark Station
IP: This is the IP address of the computer that will
receive the traffic.
Note: For security reasons, most companies will prevent computers in the production network from communicating with the APs. Ensure no firewall rules prevent the Wireshark station computer from communicating with the AP.
- Enter the Wireshark Station
IP: This is the IP address of the computer that will
receive the traffic.
- Save to file. In this mode, the AP saves a copy of the selected traffic to the controller interface. You can download the file to your local PC after you stop the capture.
- Stream to
Wireshark. In this mode the AP sends a copy of the selected
traffic to the destination computer through which this traffic can be
received and analyzed in real-time. This traffic stream stops when you click
Stop.
- Select the Capture Interface
(2.4 GHz, 5 GHz, or
6GHz/5GHz for wireless interfaces, or
Wired for the wired interfaces), and enter the
following:
- (Optional) Client MAC Address Filter: The AP only captures packets with the specified client MAC address.
- Frame Type Filter (for wireless interfaces only): The AP only captures packets with the selected type. Toggle ON the switch for the existing frame types that you want to capture:
- LAN Port (for wired interfaces only): Select the Ethernet port from the available ports in the AP.
- Click Start to start collecting the traffic.Note: You can click Close while actively collecting a packet capture to close the Packet Capture window without stopping the packet capture. This will allow you to use the controller interface to check information like client information or AP information without interrupting the capture session. Return to the Packet Capture window to stop the packet capture when required.
- Click Stop to stop collecting the traffic.
- Click Save to download
the collected file (when using the Save to file
option). Note: In the Save to file option, when you download the packet capture, the system generates a compressed archive file in .tar format with the name <AP-MAC>.tar. This file contains one or more capture<number>.pcap files, which store the captured packet data. To analyze the capture, extract the .tar file using a standard archive utility such as tar on Linux or macOS, or a tool like 7-Zip on Windows. Once extracted, open the .pcap file in a packet analysis tool such as Wireshark. From there, you can inspect protocol exchanges, filter by MAC or IP address, and identify patterns related to authentication, DHCP, roaming, or interference issues. Always verify the capture timestamp and interface type to ensure you are analyzing the correct session.