Hi all, I have basic Wireshark capture (HTTP, CAP format) I would like to put VLAN Tag label on this capture, I mean I want to have the original capture with encapsulate of VLAN ID. For this purpose I having Cisco SW Layer 2 and Layer 3 if needed and two PCs , I am using “bittwist” software to inject the XXX.CAP capture to the SW. I also tried to do span port (Monitoring port) at Layer 2 SW but I didn’t success to see VLAN tag at the destination port (I add the column of dot1q at the Wireshark Software)
Anyone can figure how to do it ?
asked 10 May '12, 00:06
I'm assuming that your CAP file (that you're injecting using bittwist) has in fact VLAN tags. If you're setting up a span port you need to tell the switch to keep the VLAN information intact, because Cisco switches remove the VLAN tag when spanning. You should set up your monitor session with the "encapsulation dot1q" parameter when defining it.
answered 10 May '12, 00:12
Have you checked whether your NIC strips the vlan tags before Wireshark gets hold of the packets? Have a look at http://wiki.wireshark.org/CaptureSetup/VLAN for instructions for configuring several NICs to not strip the vlan tags.
answered 10 May '12, 16:01