Capturing Remote Packets

Remote packet capture puts one or more APs into packet sniffer mode, allowing them to capture the wireless packets. The packets are either saved to local files or streamed to packet inspection program such as Wireshark for later analysis.
  1. From the main menu, select Tools > Packet Capture.
  2. From the Currently Managed APs table, select a specific AP checkbox and click Add to Capture APs.
    The selected AP is moved to the Capture APs table.
  3. For Radio, select 2.4 GHz, 5 GHz, or 6GHz.
  4. Select Local Mode or Streaming Mode as the capture mode.
    • To capture a limited snapshot on each AP, select Local Mode and optionally, in the Filter field, enter an IP or MAC address to filter the incoming and outgoing packets.
      1. Click Start to begin capturing packets.
      2. Click Stop to end the capture.
      3. Click Save to save the packet capture to a local file.
    • To stream the captured packets to Wireshark, select Streaming Mode.
      1. Click Start to launch Wireshark.
      2. Select Capture Options. Under Capture: Interface, select Remote. A Remote Interface dialog box is displayed.
      3. Under Host, enter the IP address of the AP you want to view. Leave the Port field empty and click OK.

        The remote host interface list on the right side is updated.

      4. Select wifi0, wifi1, or wifi2 from the list, depending on whether you are streaming on the 2.4-GHz, 5-GHz, or 6-GHz radio.

    Selecting the Capture Mode

  5. Under Currently Managed APs, select APs from the list and click Add to Capture APs.

    Adding Currently Managed APs to Capture APs

    The selected currently managed APs are moved to the Capture APs table.