This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Capwap data on Wireshark capture in a portchannel interface

0

hi, I am trying to capture the data on a port-channel connected to a wireless controller so I can see what traffic is going to and from the wireless controller from the access point and wifi client.

I am not see this traffic and only seeing some of the other traffic, for instance, I see the RDP replies\ack but not the data.

Any help would be great. I am running wireshark on a windows machine.

Mikey

asked 24 Oct '17, 08:27

MikeyConway's gravatar image

MikeyConway
6112
accept rate: 0%

Can you elaborate on your capture setup? Are you using port mirroring, a tap, what is the line speed of the port-channel and of your capturing card, ...

(25 Oct '17, 11:05) sindy

One Answer:

0

Hi, I am spanning an 8-port port channel but I resolved the issue The issues is with the MacAfee HIPS services, once that was stopped the traffic was seen correctly.

Thanks for your response.

answered 26 Oct '17, 00:15

MikeyConway's gravatar image

MikeyConway
6112
accept rate: 0%

Glad to hear that, however even if it is just 8×FE, you'd need to capture 1.6 Gbit/s at peak, so it won't fit to a single SPAN port even if it would be a GE one. Leaving alone 8×GE where you'd need to deal with 16 Gbit/s at peak which no PC is likely to manage regardless what network card you'd plug in.

(26 Oct '17, 00:22) sindy