Configuring a Remote Interface in Wireshark
APs have the capability to stream a
copy of selected network traffic to a specified remote host. This can be initiated
either
through the controller’s GUI or directly via the AP’s CLI. Once streaming is active,
the
remote host can capture and analyze the traffic using a tool like Wireshark. To analyze
the
streamed traffic, you must configure a remote capture interface in Wireshark on the
destination host.
- Open Wireshark.
- Click .
- In the Capture Options window click Manage Interfaces.
- In the Manage
Interfaces window, click the Remote Interfaces
tab and the
icon to add a remote interface.The Remote Interface window opens. - In the Remote
Interface window, enter the IP address of the AP in the field
Host
and click OK.The list of available interfaces in the AP is populated in the Manage Interfaces window.
- Click OK to close the Manage Interfaces window and return to the Capture Options window.
- In the Capture
Options window, scroll to locate and double-click the WLAN number
you want to collect the traffic from. For collecting wireless traffic select
wlan100 or wlan101.Wireshark starts to collect and display the traffic of the selected WLAN.
- Click
to
stop the current capture and click to close the capturing interface and choose a different interface
to capture. You will be prompted to save the captured data before closing or to
continue without saving. Alternatively, to restart the capture in the same
interface, after stopping the capture, click
to
restart it.Note: Stop the capture in Wireshark, save the file, and close the remote interface before stopping the traffic streaming from the AP.
%20Troubleshooting%20and%20Diagnostics%20Guide,%207.2.0_v1_GUID-9F080E15-042B-48DD-BD9D-F03E06AA985D/Wireshark%20-%20Capture%20Options%20Window=GUID-61F0FF48-F5FF-444B-868D-526733E1D2AD=1=en-US=Low.png)
%20Troubleshooting%20and%20Diagnostics%20Guide,%207.2.0_v1_GUID-9F080E15-042B-48DD-BD9D-F03E06AA985D/Wireshark%20-%20Manage%20Interfaces%20Window=GUID-13E3064C-2B70-48F8-ABAC-00BF13B77FBD=1=en-US=Low.png)