cancel
Showing results for 
Search instead for 
Did you mean: 

EXOS Packet Capture

EXOS Packet Capture

Stefan_K_
Valued Contributor

Hello,

today I played around with the built-in packet capture of EXOS ( How To: How to perform a local packet capture on an EXOS switch | Extreme Portal (force.com) )

I’m able to capture packets and open the pcap file with wireshark, but I only see the following packets:

999ffec7689143d294de259a963f2492_0cfb738b-55a4-498b-9533-89f57cd81ed1.png

Wondering if I’m doing something wrong or if the feature is something else than I’m thinking. Any hints?

Best regards
Stefan

2 ACCEPTED SOLUTIONS

CThompsonEXOS
Extreme Employee

Hi,

You can use the editcap tool to remove the first 52 bytes.  Mine looked something like below from Powershell:

PS C:\Program Files\Wireshark> .\editcap.exe -C 52 editcap.pcap newpcap.pcap

syntax below:
PS C:\Program Files\Wireshark> .\editcap.exe -C 52 <original pcap filename> <new pcap filename>

Below is more on editcap:

https://www.wireshark.org/docs/man-pages/editcap.html

Before:

83850ff01e9c44fd92c42a4a8fa2122d_701970b3-7509-4c5a-9bf0-a8dab60f51b4.png

 

After:

83850ff01e9c44fd92c42a4a8fa2122d_65f32e5a-5e2a-4a35-96da-75256f170e72.png

 

Thanks,

Chris Thompson

View solution in original post

booflix
New Contributor III

This is an interesting question because the built-in packet capture feature can be a bit confusing at first. If you're only seeing those packets in Wireshark, it may be related to the capture point, applied filters, or hardware offloading rather than the traffic itself. Checking the interface configuration and testing with a known traffic Gomovies flow could help narrow down the cause. I'd be interested to know what the final solution was, as it could be useful for anyone troubleshooting EXOS packet captures in the future.

View solution in original post

19 REPLIES 19

booflix
New Contributor III

It sounds like the packet capture itself is working since you’re able to export the Cineby  pcap file and open it in Wireshark. In many cases with EXOS, seeing only a limited set of packets usually means the capture point or filter is restricting what the switch mirrors to the capture process. By default, the built-in capture may only see traffic that is processed by the CPU (control-plane traffic) rather than all data-plane traffic passing through the ports.

booflix
New Contributor III

t sounds like the packet capture itself is working since you’re able to generate the pcap file and open it in Wireshark. If you’re only seeing a very limited set of packets Wooflix  (for example control-plane traffic like ARP, STP, LLDP, etc.), then it’s likely not a malfunction but rather how the built-in capture on ExtremeXOS (EXOS) is designed to operate.

CThompsonEXOS
Extreme Employee

Hi Stefan,

You bring upa good point(Stefan 1, Chris 0) so that article has been updated:

 

How To: How to perform a local packet capture on an EXOS switch | Extreme Portal (force.com)

 

Thanks again,

Chris Thompson

Stefan_K_
Valued Contributor

Hi Chris,

this worked like a charm, thank you very much! How much “trouble” some 52 bytes can cause… 🙂

Maybe this little information can be added to the GTAC articles?

 

Best regards
Stefan

CThompsonEXOS
Extreme Employee

Hi,

You can use the editcap tool to remove the first 52 bytes.  Mine looked something like below from Powershell:

PS C:\Program Files\Wireshark> .\editcap.exe -C 52 editcap.pcap newpcap.pcap

syntax below:
PS C:\Program Files\Wireshark> .\editcap.exe -C 52 <original pcap filename> <new pcap filename>

Below is more on editcap:

https://www.wireshark.org/docs/man-pages/editcap.html

Before:

83850ff01e9c44fd92c42a4a8fa2122d_701970b3-7509-4c5a-9bf0-a8dab60f51b4.png

 

After:

83850ff01e9c44fd92c42a4a8fa2122d_65f32e5a-5e2a-4a35-96da-75256f170e72.png

 

Thanks,

Chris Thompson

GTM-P2G8KFN