Hi Guys, Got a bit of a strange one with a IP phone using an untagged voice vlan and a untagged data vlan. I am capturing the traffic through a 3750x for the following int:
mirroring the port: Session 1
If i use laptop #1:
it works fine when i capture and filter: ip.addr==ip phone ip However as i need to capture a call at multiple locations, i need another machine with wireshark: Laptop#2 :
I'm unable to see any packets for the untagged voice vlan 107 even through im using the same syntax and same destination port and cable. I have tried this on multiple different machines and it seems that anything relatively new doesnt work Any help would be greatly appreciated, thank you Rich asked 17 Mar '15, 08:25 RJE edited 17 Mar '15, 09:48 |
One Answer:
First of all, your configuration makes the switch forward the voice packets with a 802.1Q tag of 107. Have a look at http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2950/software/release/12-1_11_yj/configuration/guide/scg/swvoip.html:
Whether vlan tagged frames are being discarded or forwarded with the vlan tags stripped or as is depends on the registry settings for the NIC driver. Have a look at https://wiki.wireshark.org/CaptureSetup/VLAN#Windows for more info on how to capture vlan tagged packets. answered 17 Mar ‘15, 12:13 SYN-bit ♦♦ |
Thanks for the reply Syn-bit, trying out these fixes now