Configuring a Remote Interface in Wireshark

APs have the capability to stream a copy of selected network traffic to a specified remote host. This can be initiated either through the controller’s GUI or directly via the AP’s CLI. Once streaming is active, the remote host can capture and analyze the traffic using a tool like Wireshark. To analyze the streamed traffic, you must configure a remote capture interface in Wireshark on the destination host.
Make sure the following prerequisites are met:
  • Wireshark is installed on your computer.
  • Network connectivity between the AP and your computer is established:
    • The AP and the computer do not need to be on the same subnet.
    • The computer does not need to be wirelessly connected to the AP.
    • However, the AP must be able to reach the computer. Ensure that any firewall rules that might block this traffic are disabled.
  • Start traffic streaming from the AP before configuring the remote interface in Wireshark.
Complete the following steps to configure a remote interface in Wireshark and start collecting the streaming traffic received from the AP.
  1. Open Wireshark.
  2. Click Capture > Options.
    The Capture Options window opens.

    Wireshark - Capture Options

  3. In the Capture Options window click Manage Interfaces.
    The Manage Interfaces window opens.

    Wireshark - Manage Interfaces

  4. In the Manage Interfaces window, click the Remote Interfaces tab and the icon to add a remote interface.
    The Remote Interface window opens.
  5. In the Remote Interface window, enter the IP address of the AP in the field Host and click OK.
    The list of available interfaces in the AP is populated in the Manage Interfaces window.
  6. Click OK to close the Manage Interfaces window and return to the Capture Options window.
  7. In the Capture Options window, scroll to locate and double-click the WLAN number you want to collect the traffic from. For collecting wireless traffic select wlan100 or wlan101.
    Wireshark starts to collect and display the traffic of the selected WLAN.
  8. Click to stop the current capture and click File > Close to close the capturing interface and choose a different interface to capture. You will be prompted to save the captured data before closing or to continue without saving. Alternatively, to restart the capture in the same interface, after stopping the capture, click to restart it.
    Note: Stop the capture in Wireshark, save the file, and close the remote interface before stopping the traffic streaming from the AP.