Configuring Local Packet Capture

Using the Local Packet Capture feature, you to capture and analyze network traffic directly on your device. Local Packet Capture provides granular insights into data packets, enabling you to understand network behavior and proactively address potential security vulnerabilities.
Complete the following steps to configure the Local Packet Capture feature.
  1. Enter the monitor capture command to specify the interface from which you want packets to be captured.
    device# monitor capture packet-cap interface ethernet 1/1/1

    A packet capture name, "packet-cap" is configured for an Ethernet interface.

  2. Enter the monitor capture match command to apply capture filters.
    device# monitor capture packet-cap match ip any any

    Any source IP address and any destination IP address are matched.

  3. (Optional) Enter the monitor capture limit command to set capture limits.
    The default packet capture length is 68 bytes.
    device# monitor capture packet-cap limit duration 10 packets 100

    The capture limit is set to 10 seconds and a maximum of 100 packets.

  4. (Optional) Enter the monitor capture buffer size command to specify the size of the capture buffer in kilobytes.
    That default buffer size is 2097152 bytes.
    device# monitor capture packet-cap buffer size 512
    A buffer size of 512 KB for packet capture is set. The buffer, interface, filters, and limits are set, you can start capturing packets.
  5. Enter the monitor capture start command to start packet capture.
    device# monitor capture start

    The packet capture session starts.

  6. Enter the monitor capture stop command to stop packet capture.
    device# monitor capture stop

    The packet capture session stops.

  7. Enter the copy flash command to export captured packets.
    device# copy flash tftp 10.177.16.145 packet_capture_2024_05_04_13_34_49.pcap

    The "packet_capture_2024_05_04_13_34_49.pcap" file is exported to "10.177.16.145" using TFTP.

    After stopping a packet capture session, you can export the captured packets to a TFTP server for analysis.
  8. Enter the show monitor capture command to view details of the captured packets.
    device# show monitor capture
    Configured packet capture is:- 'packet-cap'
    device# show monitor capture packet-cap
    Capture Name :packet-cap
    Last generated pcap file :packet_capture_2024_05_04_13_34_49.pcap
    Target Type :
     Interface Type : 1/1/1, Direction : in
     Status : Active
    Filter Details :
    source ip:10.1.1.1
    source mask:
    destination ip:10.2.1.1
    destination mask:0.0.0.255
    Buffer Details :
     Buffer Type : linear (Default)
     Buffer Size (in KB) : 2097152
    Limit Details :
     Number of packets to capture : 150
     Packet Capture Duration :15
     
  9. Enter the monitor capture clear command to clear the buffer after capturing packets.
    device# monitor capture packet-cap clear

    The buffer is cleared.

  10. Enter the monitor capture delete command to delete captured files.
    This example deleted the captured file named, "packet_capture_2024_06_24_06_43_12.pcap"
    device# monitor capture delete packet_capture_2024_06_24_06_43_12.pcap
    This deletes the capture file packet_capture_2024_06_24_06_43_12.pcap.

The following example enables packet capture on the interface (Ethernet 1/1/1), capturing all IP packets, limiting the capture to 10 seconds or 100 packets, setting a buffer size of 512 bytes, starting the capture, displaying the capture status, and clearing the captured packets.

device# monitor capture packet-cap interface ethernet 1/1/1
device# monitor capture packet-cap match ip any any
device# monitor capture packet-cap limit duration 10 packets 100
monitor capture packet-cap buffer size 512
device# monitor capture start
device# show monitor capture packet-cap
device# monitor capture packet-cap clear