This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Capturing FTP on mirrored port not working

0

Hi,

We have Extreme switches in our environment and I'm trying to capture FTP traffic between a copier on my network and a file server.

  • I mirrored the copier port
  • Plugged a laptop into the mirrored port
  • Started Wireshark capture in promiscuous mode
  • Scanned a document on the copier which opens and FTP connection to our file server
  • No FTP traffic appears in the capture

OK. Let's see if I Wireshark can pick up the FTP traffic natively from my laptop, with no port mirroring

  • Opened Wireshark on my laptop ... capturing in promiscuous mode
  • established and FTP connection with the file server via CLI
  • Observed FTP protocol in Wireshark capture (Success!)

OK. So it's not my config of Wireshark. It is picking up FTP traffic natively from my laptop. So let's mirror the port my laptop is in and try again

  • I mirrored my laptop port on the swtich
  • Plugged a new laptop into the mirrored port
  • Opened Wireshark on the new laptop... capturing again in promiscuous mode
  • established an FTP connection from my laptop to the file server via CLI
  • No FTP traffic captured

This leads me to believe that there is something about the mirroring process on my switches that is not sending FTP traffic to a mirrored port. I know not everyone has Extreme switches, but has anyone heard of such behavior in their own environments?

Thanks for listening and I appreciate any help.

Regards, Joe

asked 23 Sep '15, 11:29

JoeyJoeJoe1970's gravatar image

JoeyJoeJoe1970
1222
accept rate: 0%

Do you see any traffic on that mirrored port?

(23 Sep '15, 12:58) Kurt Knochner ♦

Hi Kurt.

Yes I see plenty of traffic coming through. Just no FTP protocol.

(23 Sep '15, 13:01) JoeyJoeJoe1970

One Answer:

0

Yes I see plenty of traffic coming through. Just no FTP protocol.

well, then it's neither a problem with Wireshark nor a general problem with your port mirroring, so you should ask this question in a Extreme Networks forum, because your chances to get a usefull answer will be much higher.

Regards
Kurt

answered 23 Sep '15, 13:05

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%