05-18-2021 01:00 PM
Hello,
today I played around with the built-in packet capture of EXOS ( How To: How to perform a local packet capture on an EXOS switch | Extreme Portal (force.com) )
I’m able to capture packets and open the pcap file with wireshark, but I only see the following packets:
Wondering if I’m doing something wrong or if the feature is something else than I’m thinking. Any hints?
Best regards
Stefan
Solved! Go to Solution.
05-18-2021 03:54 PM
Hi,
You can use the editcap tool to remove the first 52 bytes. Mine looked something like below from Powershell:
PS C:\Program Files\Wireshark> .\editcap.exe -C 52 editcap.pcap newpcap.pcap
syntax below:
PS C:\Program Files\Wireshark> .\editcap.exe -C 52 <original pcap filename> <new pcap filename>Below is more on editcap:
https://www.wireshark.org/docs/man-pages/editcap.html
Before:
After:
Thanks,
Chris Thompson
07-21-2026 09:42 PM - edited 07-21-2026 09:43 PM
This is an interesting question because the built-in packet capture feature can be a bit confusing at first. If you're only seeing those packets in Wireshark, it may be related to the capture point, applied filters, or hardware offloading rather than the traffic itself. Checking the interface configuration and testing with a known traffic Gomovies flow could help narrow down the cause. I'd be interested to know what the final solution was, as it could be useful for anyone troubleshooting EXOS packet captures in the future.
07-19-2026 08:34 PM - edited 07-19-2026 08:34 PM
Hi Stefan,
It looks like you're only capturing control-plane traffic rather than the data-plane packets you're expecting. A few things you might want to check:
Could you share your switch model, EXOS version, and the exact capture command you used? That would make it easier to determine whether you're hitting a platform limitation or a configuration issue.
07-08-2026 12:47 PM
This was an enjoyable read from beginning to end. The explanations were straightforward, the examples felt relevant, and I finished with a much better understanding of the subject overall.
Visit
04-26-2026 11:18 AM - edited 04-26-2026 11:18 AM
It sounds like you’ve successfully captured traffic, but what you’re seeing in Wireshark suggests the capture might be limited in scope rather than “full” packet visibility. EXOS GMovies packet capture is often interface- and filter-dependent, so if you’re only seeing a small subset of frames (like control or broadcast traffic), it could be due to the capture point, VLAN context, or applied filters.
04-22-2026 12:42 PM - edited 04-22-2026 12:42 PM
It sounds like the capture itself is working since you’re able to open the file in Wireshark, but the fact that you’re only seeing a limited or unexpected set of packets usually points to how (and where) the capture is being performed on EXOS.
One thing to keep in mind is that the built-in packet capture on EXOS doesn’t always behave like a full mirror/SPAN port. Depending on the configuration, it may only capture control-plane traffic or packets destined to/from the switch CPU, rather than all transit traffic on a port or VLAN. That could explain why your capture looks incomplete. Visit
03-13-2026 09:12 PM - edited 03-13-2026 09:12 PM
It sounds like the packet capture itself is working since you’re able to export the Cineby pcap file and open it in Wireshark. In many cases with EXOS, seeing only a limited set of packets usually means the capture point or filter is restricting what the switch mirrors to the capture process. By default, the built-in capture may only see traffic that is processed by the CPU (control-plane traffic) rather than all data-plane traffic passing through the ports.