On Cisco 2811 router, I type the following configuration:
I open Wireshark on the PC and try to capture the network traffic of the 2811 router I type the IP of the 2811 router as the "Remote" host IP and click "OK" But Wireshark claim that the 2811 router reject the connection What else can I do for Wireshark capture the network traffic of the 2811 router ? asked 04 May '11, 08:55 andresbag edited 04 May '11, 09:13 SYN-bit ♦♦ |
One Answer:
The ip traffic-export functionality of the cisco is not related to the remote capture functionality in Wireshark. For remote capture functionality, you will need a second system with WinPcap running and rpcapd running. The cisco ip traffic-export will send a copy of the selected traffic to the configured mac-address. If that mac-address is of the Wireshark PC and the WIreshark PC is directly connected to the listed interface, then you should be able to see the copied traffic. answered 04 May '11, 09:16 SYN-bit ♦♦ |