Configuring Local Packet Capture
Using the Local Packet Capture feature, you to capture and analyze network traffic
directly on your device. Local Packet Capture provides granular insights into data
packets,
enabling you to understand network behavior and proactively address potential security
vulnerabilities.
- Enter the
monitor capturecommand to specify the interface from which you want packets to be captured. - Enter the
monitor capture matchcommand to apply capture filters. - (Optional) Enter the
monitor capture limitcommand to set capture limits.The default packet capture length is 68 bytes. - (Optional) Enter the
monitor capture buffer sizecommand to specify the size of the capture buffer in kilobytes.That default buffer size is 2097152 bytes.A buffer size of 512 KB for packet capture is set. The buffer, interface, filters, and limits are set, you can start capturing packets. - Enter the
monitor capture startcommand to start packet capture. - Enter the
monitor capture stopcommand to stop packet capture. - Enter the
copy flashcommand to export captured packets.device# copy flash tftp 10.177.16.145 packet_capture_2024_05_04_13_34_49.pcap
The "packet_capture_2024_05_04_13_34_49.pcap" file is exported to "10.177.16.145" using TFTP.
After stopping a packet capture session, you can export the captured packets to a TFTP server for analysis. - Enter the
show monitor capturecommand to view details of the captured packets.device# show monitor capture Configured packet capture is:- 'packet-cap'
device# show monitor capture packet-cap Capture Name :packet-cap Last generated pcap file :packet_capture_2024_05_04_13_34_49.pcap Target Type : Interface Type : 1/1/1, Direction : in Status : Active Filter Details : source ip:10.1.1.1 source mask: destination ip:10.2.1.1 destination mask:0.0.0.255 Buffer Details : Buffer Type : linear (Default) Buffer Size (in KB) : 2097152 Limit Details : Number of packets to capture : 150 Packet Capture Duration :15
- Enter the
monitor capture clearcommand to clear the buffer after capturing packets. - Enter the
monitor capture deletecommand to delete captured files.
The following example enables packet capture on the interface (Ethernet 1/1/1), capturing all IP packets, limiting the capture to 10 seconds or 100 packets, setting a buffer size of 512 bytes, starting the capture, displaying the capture status, and clearing the captured packets.
device# monitor capture packet-cap interface ethernet 1/1/1 device# monitor capture packet-cap match ip any any device# monitor capture packet-cap limit duration 10 packets 100 monitor capture packet-cap buffer size 512 device# monitor capture start device# show monitor capture packet-cap device# monitor capture packet-cap clear