Users Guide

Table Of Contents
Layer 2 Switching Commands 716
If capturing is in progress, the show monitor capture packets command
displays only the captured packets that have not yet been displayed during the
capturing session. If capturing is stopped, the first (after stopping) show
monitor capture packets command displays the packets that have not yet
been displayed during the capturing session. The next show monitor capture
packets command displays up to 128 captured packets.
If the capturing session is stopped automatically when the packet display is in
progress, then packet display continues until all packets are shown. The next
call of the show capture packets command displays nothing. Please note that
such behavior is observed only if the capturing session is stopped
automatically when the packet display is in progress.
NVRAM Capture:
After packet capture is activated, packets are stored in NVRAM until the
capture file reaches its maximum size, or until the capture is stopped
manually. When the capture is started the capture file from the previous
capture is deleted.
The captured file can be uploaded via TFTP, SFTP, SCP via CLI, and SNMP
using the copy command. The name of the capture file is
cpuPktCapture.pcap.
Remote Capture:
Remote Packet Capture works with the Wireshark network analyzer tool. A
packet capture server runs on the switch and sends the captured packets via a
TCP connection to the Wireshark tool. Once a connection is established,
packet capture is started and stopped via Wireshark commands.
Remote capture can be enabled or disabled using the CLI. The network
operator should obtain a computer with the Wireshark tool to display the
captured traffic. When using remote capture mode, the switch doesn’t store
any captured data locally.
The local TCP port number can be configured for connecting Wireshark to
the switch. The default port number is 2002. If a firewall is installed between
the Wireshark PC and the switch, these ports must be allowed to pass
through the firewall. The Firewall must be configured to allow the Wireshark
PC to initiate a TCP connection to the switch.