<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Log traffic between two end points? in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/log-traffic-between-two-end-points/m-p/58073#M17206</link>
    <description>What I've done in the past is port-mirroring, where you can even mirror a port to a remote-port, meaning your wireshark/whatever probe can site on a completely different switch.&lt;BR /&gt;
&lt;BR /&gt;
The other option is to tcpdump locally ON the switch. Yes, there's a packet capture command! Of course you may not want to keep that running forever - the switch does have limited space...&lt;BR /&gt;
I usually just need to troubleshoot things and capture a few minutes of traffic, then tftp the captured file to a server and read it through wireshark after the capture. You could possibly even script that (capture this much data, stop, transfer file, erase file, start capturing again, rinse-repeat)&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-perform-a-local-packet-capture-on-an-EXOS-switch" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-perform-a-local-packet-capture-on-a...&lt;BR /&gt;
&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/Perform-a-packet-capture-in-the-EXOS-CLI-using-the-command-debug-packet-capture" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/Perform-a-packet-capture-in-the-EXOS-CLI-using-the-command-debug-packet-capture&lt;/A&gt;   That's the one I usually go by.&lt;BR /&gt;
&lt;BR /&gt;
Sorry, wanted to reply 2 days ago...&lt;BR /&gt;
&lt;BR /&gt;
   Frank&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Wed, 01 Aug 2018 16:03:00 GMT</pubDate>
    <dc:creator>Frank</dc:creator>
    <dc:date>2018-08-01T16:03:00Z</dc:date>
    <item>
      <title>Log traffic between two end points?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/log-traffic-between-two-end-points/m-p/58072#M17205</link>
      <description>I have the following extreme switches running layer 2 and layer 3 for our organisation:&lt;BR /&gt;
&lt;BR /&gt;
X670 G1 Firmware 16.2.2.4&lt;BR /&gt;
X670 G2 Firmware 21.1.1.4&lt;BR /&gt;
&lt;BR /&gt;
What is my easiest option for capturing layer 3 conversations from a source IP range?&lt;BR /&gt;
&lt;BR /&gt;
I'd like to know what hosts in our DMZ are communicating to internal servers, so basically just capture anything with a source of x.x.x.x/27&lt;BR /&gt;
&lt;BR /&gt;
Perhaps something like remote mirroring the inbound ISP ports to a Linux machine running TCPDUMP to capture, or a windows box running wireshark with a filter?</description>
      <pubDate>Fri, 06 Apr 2018 07:15:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/log-traffic-between-two-end-points/m-p/58072#M17205</guid>
      <dc:creator>Ben_Giles</dc:creator>
      <dc:date>2018-04-06T07:15:00Z</dc:date>
    </item>
    <item>
      <title>RE: Log traffic between two end points?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/log-traffic-between-two-end-points/m-p/58073#M17206</link>
      <description>What I've done in the past is port-mirroring, where you can even mirror a port to a remote-port, meaning your wireshark/whatever probe can site on a completely different switch.&lt;BR /&gt;
&lt;BR /&gt;
The other option is to tcpdump locally ON the switch. Yes, there's a packet capture command! Of course you may not want to keep that running forever - the switch does have limited space...&lt;BR /&gt;
I usually just need to troubleshoot things and capture a few minutes of traffic, then tftp the captured file to a server and read it through wireshark after the capture. You could possibly even script that (capture this much data, stop, transfer file, erase file, start capturing again, rinse-repeat)&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-perform-a-local-packet-capture-on-an-EXOS-switch" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-perform-a-local-packet-capture-on-a...&lt;BR /&gt;
&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/Perform-a-packet-capture-in-the-EXOS-CLI-using-the-command-debug-packet-capture" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/How_To/Perform-a-packet-capture-in-the-EXOS-CLI-using-the-command-debug-packet-capture&lt;/A&gt;   That's the one I usually go by.&lt;BR /&gt;
&lt;BR /&gt;
Sorry, wanted to reply 2 days ago...&lt;BR /&gt;
&lt;BR /&gt;
   Frank&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 01 Aug 2018 16:03:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/log-traffic-between-two-end-points/m-p/58073#M17206</guid>
      <dc:creator>Frank</dc:creator>
      <dc:date>2018-08-01T16:03:00Z</dc:date>
    </item>
  </channel>
</rss>

