Installing and Using Wireshark for Capturing Network Traffic



Similar documents
Lab - Configure a Windows Vista Firewall

Lab - Configure a Windows 7 Firewall

Technical Note. Monitoring Ethernet Traffic with Tolomatic ACS & Managed Switch. Contents

Lab Conducting a Network Capture with Wireshark

Print Server Application Guide

24 Port Gigabit Ethernet Web Smart Switch. Users Manual

Using Cisco UC320W with Windows Small Business Server

6.0. Getting Started Guide

MS Series: VolP Deployment Guide

Integration with IP Phones

In this lab you will explore the Windows XP Firewall and configure some advanced settings.

How to monitor network traffic inside an ESXi host

Centurion PLUS CPC4 Download Guide

Print Server Application Guide. This guide applies to the following models.

Link Link sys E3000 sys RE1000

University Computing & Telecommunications Virtual Private Networking: How To/Self- Help Guide Windows 8.1 Operating System.

Lab - Configure a Windows XP Firewall

Cisco Linksys SPA 2102

How to Add and Remove Virtual Hardware to a VMware ESXi Virtual Machine

CS 326e F2002 Lab 1. Basic Network Setup & Ethereal Time: 2 hrs

Lab - Using Wireshark to View Network Traffic

Back Office Recorder 4iP Installation Guide Intelligent Recording Limited

Understanding offline files

ipad Installation and Setup

P-2612HNU-Fx n ADSL2+ VoIP IAD DEFAULT LOGIN DETAILS. Firmware V3.00 Edition 1, 1/2010. Password: 1234 User Name: admin Password: 1234

VersaLink 7500 Gateway Troubleshooting

INSTALLING AND USING ENTEL PROGRAMMER IN WINDOWS 7 Technical Support Bulletin

DLink-655 Router Configuration Guide for VoIP

How to register and use our Chat System

NETVIGATOR Wireless Modem Setup Guide. (TG789Pvn)

Darstellung Unterschied ZyNOS Firmware Version 4.02 => 4.03

Broadband Phone Gateway BPG510 Technical Users Guide

CCRecord Professional SIP Trunk Recording. Application Notes

Virtual Office Remote Installation Guide

Using the VEX Cortex with ROBOTC

Network Agent Quick Start

Desktop NETGEAR Genie

Crown Field Support Engineering

Introduction to Wireshark Network Analysis

Apple Airport Extreme Base Station V4.0.8 Firmware: Version 5.4

P-660HW-Tx v g Wireless ADSL2+ 4-port Gateway DEFAULT LOGIN DETAILS. Firmware v3.70 Edition 1, 2/2009

Procedure for updating Firmware of EZ4 W or ICC50 W

Enabling Internet Connection Sharing on Windows Enabling ICS On Windows XP As The Host 4 Enabling ICS On Windows XP As The Client 11

UIP1868P User Interface Guide

integration tools setup guide SIM 3 Remote Guide to controlling a SIM 3 Audio Analyzer remotely over a network connection from a laptop

16-PORT POWER OVER ETHERNET WEB SMART SWITCH

Movie Cube. User s Guide to Wireless Function

A Guide to Simple IP Camera Deployment Using ZyXEL Bandwidth Solutions

Linksys Wireless G WRT54G

Lab VI Capturing and monitoring the network traffic

Microsoft Office 365 with MailDefender

How to Create VLANs Within a Virtual Switch in VMware ESXi

Connecting to Remote Desktop Windows Users

ProSAFE 8-Port and 16-Port Gigabit Click Switch

P-660HW-Tx v3. Quick Start Guide g Wireless ADSL 2+ 4-port Gateway. Version /2008 Edition 1

Direct Attached Storage


To ensure you successfully install Timico VoIP for Business you must follow the steps in sequence:

TE100-P21/TEW-P21G Windows 7 Installation Instruction

Firewall Rules (Outbound)

Link and Sync Guide for Hosted QuickBooks Files

PLA Series. User s Guide. Quick Start Guide. Powerline Ethernet Adapters. PLA4101, PLA4111, PLA4201, PLA4201 v2, PLA5205, PLA5215, PLA5206, PLA5405

Network Security: Workshop

StarMOBILE Network Configuration Guide. A guide to configuring your StarMOBILE system for networking

How to use SURA in three simple steps:

Lab Configuring Access Policies and DMZ Settings

USB HSPA Modem. User Manual

OM2260VW2 USER MANUAL VERIZON WIRELESS HOME PHONE CONNECT

ScanWin Installation and Windows 7-64 bit operating system

Optimum Business SIP Trunk Set-up Guide

Ethernet Radio Configuration Guide

Packet Tracer - Connecting a Wired and Wireless LAN Topology

iinet ATA Telephone Adapter

Computer Networks I Laboratory Exercise 1

Setting Up Your FTP Server

User guide. Business

Configuring WAN Failover with a Cisco 881 Router and an AirLink ES440

Network Setup Guide. 1 Glossary. 2 Operation. 1.1 Static IP. 1.2 Point-to-Point Protocol over Ethernet (PPPoE)

DIRECT INTERNET DATA. User s Guide

USER GUIDE AC2600 MU-MIMO GIGABIT ROUTER. Model# EA8500

User Guide. E-Series Routers

WORKING WITH WINDOWS FIREWALL IN WINDOWS 7

A Division of Cisco Systems, Inc. GHz g. Wireless-G. Access Point with SRX. User Guide WIRELESS WAP54GX. Model No.

Dynamic VLAN assignment using RADIUS. Network Diagram

Application Note Gigabit Ethernet Port Modes

Quick Start Guide. Cisco SPA232D Mobility Enhanced ATA

School of Information Technology and Engineering (SITE) CEG 4395: Computer Network Management

Troubleshooting the Verizon MI424WR Router

Centurion C4 Transfer Guide using C4 File Transfer Utility

Installing Remote Desktop Connection

Linksys E-Series Routers. User Guide

Global Monitoring + Support

Virtual COM Port Driver Installation Manual

Virtual COM Port Driver Installation Manual

User s Manual for Fingerprint Door Control Software

CMP-102U. Quick Installation Guide

P-660HWP-Dx. Quick Start Guide g HomePlug AV ADSL2+ Gateway. Version /2007 Edition 1. Copyright All rights reserved.

Network Monitoring User Guide Pulse Appliance

SIP Trunking using Optimum Business Sip Trunk Adaptor and the Zultys MX250 IP PBX

How To Use An Eyefi Card With A Wireless Network On A Iphone Or Ipad Or Ipa (For A Computer) With A Camera On A Blackberry Or Ipo (For An Ipo) With An Eyefi Card

Transcription:

Installing and Using Wireshark for Capturing Network Traffic These instructions are written for using a Windows computer, but are mostly valid for a Linux/Apple environment too. In order to better troubleshoot issues with your ATA, you can capture all network traffic off of the network cable and submit to Cisco as follows. Downloading Wireshark Download the most current version of Wireshark from http://wireshark.org/download.html Install Wireshark and WinPcap and accept all defaults. [Additional help is located at: http://www.wireshark.org/docs/wsug_html_chunked/chbuildinstallwininstall.html ] SPA122 all firmware versions Page 1 of 11 November 30 th 2012

Network Interfaces on Computer You need to understand a little about your network in order to properly collect all network traffic. For example, your computer may be on a data VLAN and your ATA may be on a voice VLAN without you realizing it. For this reason, I recommend that you use a separate network interface for Wireshark such as a USB NIC [network interface card/connector]. I use the Cisco Linksys USB Ethernet Adaptor with great success. Using an additional adaptor allows my computer to remain connected to the network via its regular interface [wired or wireless, it doesn't matter] while my Wireshark USB NIC is connected to a switch port that is mirrored [also known as being in "span" mode] so that all switch data is seen by my Wireshark interface. You must configure your network switch so that it copies (mirrors) network data to the Wireshark port. [Switches, by design, do not send all network traffic to all ports. Read more here if you're interested.] SPA122 all firmware versions Page 2 of 11 November 30 th 2012

Configuring Mirroring on the Network Switch Here's an example of configuring a Cisco SG300 10P switch: 1. Log in to the switch as an administrative user. 2. Decide which port will be the mirror/span target. In my lab, I usually use the right most port as the mirror target, making it easier for me to remember which port does what. Only one port can be a mirror target but multiple ports can be configured as mirror source ports. 3. Navigate to Administration > Diagnostics > Port and VLAN Mirroring: a. Click Add to display the Add Port and VLAN Mirroring pop up window. b. Select the Destination Port. I changed from the default of GE1 to GE10. c. Select the Source Interface. This is the port to which your ATA is connected and whose network traffic you want to see. In this example, I use GE1. [Leave VLAN unselected] d. Select the Type of Tx and Rx to allow you to see all network traffic transmitted (Tx) and received (Rx) by the connected ATA. e. Click Apply. SPA122 all firmware versions Page 3 of 11 November 30 th 2012

f. The Port and VLAN Mirroring Table is updated with the change: g. Save the switch's configuration. 4. Connect to port GE10 of the switch, the network cable from the Wireshark interface. 5. Connect to port GE1 of the switch, the network cable from the ATA that you want to monitor. 6. You've now completed configuring the network switch. SPA122 all firmware versions Page 4 of 11 November 30 th 2012

Using Wireshark Wireshark is extremely capable and very powerful. This section provides the bare minimum information to get you started. The Wireshark University provides an excellent source of deep technical training on using Wireshark and protocol analysis. Starting Wireshark for the First Time Make sure that the network interface that you plan to use for Wireshark captures is properly connected to your computer and to the network switch, or else Wireshark may not properly detect the interface when Wireshark starts up. Locate the Wireshark shortcut on your desktop if you installed a shortcut during Wireshark installation. Otherwise, click Start > All Programs > and locate and double click the Wireshark icon Wireshark will load its configuration files and display its progress: Once Wireshark is running, its main interface will display: SPA122 all firmware versions Page 5 of 11 November 30 th 2012

SPA122 all firmware versions Page 6 of 11 November 30 th 2012

Selecting a Wireshark Capture Interface You must select an interface from the available interfaces on your computer. In this example, I'll select the USB2.0 to Fast Ethernet Adapter from the list: If you are not sure which interface to use, click Interface List to view details about each interface which may help with your selection: SPA122 all firmware versions Page 7 of 11 November 30 th 2012

You can also click the Details button if you need more help selecting the appropriate interface: Once you've selected the appropriate interface, click Options to make user display selections: I find these options to be best for my every day use: SPA122 all firmware versions Page 8 of 11 November 30 th 2012

Starting a Capture You're finally ready to start your first capture. Click any of the Start buttons: Or: Or: SPA122 all firmware versions Page 9 of 11 November 30 th 2012

Wireshark will display the capture window: SPA122 all firmware versions Page 10 of 11 November 30 th 2012

Stopping and Saving a Capture Once you have replicated the scenario that you wanted to capture, for example, the SPA ATA's network behavior when power is applied to it, you must stop the capture by clicking on the stop icon: Once the capture is stopped, click the save icon: When saving the Wireshark trace, be sure to use a descriptive name to help you easily recall why you captured the trace. You can now locate the trace on your storage device and compress it and share with someone for analysis. <end> SPA122 all firmware versions Page 11 of 11 November 30 th 2012