Local Packet Capture
Feature Overview
The Local Packet Capture feature allows you to capture and analyze network traffic directly on your device. It enhances network security by providing detailed insights into data packets, helping you understand network behavior and address security vulnerabilities proactively.
The Local Packet Capture feature supports the following customizations:
- Packet Type: You can specify packet types, such as IPv4 or IPv6.
- Maximum Capture Size: You can set the maximum capture size for the data packets.
- Export Capability: You can export captured packets as .pcap files using TFTP or secure copy protocol (SCP) to external servers for in-depth analysis.
To use the Local Packet Capture
feature, create a capture name, specify the desired interface, port, and filter
criteria, using the match command, and start capturing packets based on the specified
criteria. For more information, refer to the RUCKUS FastIron Command
Reference. You can temporarily store data packets for later examination
and analyze the captured packets to identify issues or trends. Optionally, export
the captured packets as .pcap files for further analysis or storage.
Requirements
This feature has no special hardware or software requirements for feature enablement or usage.
Considerations
Prerequisites
This feature has no prerequisites to feature enablement or usage.
Limitations
- ACL Priority: If any ACL in the "All Combo" group has a higher priority than the Local Packet Capture ACL, the ACL takes precedence, preventing packet capture.
- Packet Types: Only data packets can be captured; control packets cannot be captured.
- Single Interface: Only one interface can be used for packet capture at a time.
- Capture Rate Limit: The capture rate is limited to a maximum of 1000 packets per second (pps).
- Single Capture: Only one capture can be active at a time.
- Single Interface Binding: Only one interface can be bound for packet capture.
- Ingress Traffic Only: Local Packet Capture can capture inbound traffic only.
- IPv4/IPv6 Only: Only IPv4 and IPv6 packets can be captured.
- IPv6 Source Address Limitations: Specific IPv6 source addresses cannot be captured.
- File Storage: A maximum of four .pcap files can be stored in flash memory.
- Capture Duration: Packet capture is limited to 60 seconds.
- Interference: Certain network functions, such as pinging associated IP addresses, may not work as expected when Local PCAP is enabled.