Remote Packet Capture (rpcap)
How it Works
- Set the mirror on BOLT
- This defines what traffic will be mirrored to the target port.
- Eth2 is the port on the OLT that is used for capture
- Standard Port 2002 is used on OLT for remote wireshark connection
- Enable rpcap - this begins exposing the wireshark interface to the user.
- Start wireshark on the remote computer.
- Use wireshark remote pcap interface to connect to the OLT.
- Connect to eth2, port 2002.
- Perform capture.
- Disable RPCAP on the OLT.
Video
Command Syntax
Mirror Command
- Tolt diagnostics flowmirror
- Dir – ingress/egress/both, defines the direction to mirror.
- Mac-filter – A mac to filter on so can constrain to a single source/destination.
- Net-interface – Use a NET as the source of the mirror.
- Nni-interface – Mirror an individual uplink port.
- Pon-interface – Mirror a PON port's traffic
- Target – The target port to send the mirror to. Default is the cpu (eth2). It can also mirror to ports to allow surveillance for applications such as forescout.
- Vlan – A vlan number 2..4094 or any.
Rpcap Command
- Tolt diagnostics rpcap
- Enable – Enable the OLT to expose rpcap interface
- Disable – Disable rpcap and close rpcap port
Remote Packet Capture Example
The following example will show how to capture a packet from the BOLT.
- The first step will display the available completions of the flowmirror command.
- From the MDS1-ESUA# command line, input tolt diagnostics flowmirror enable, and question mark Output similar to the following is displayed showing all the action parameters:
MDS1-ESUA# tolt diagnostics flowmirror enable <enter>
Possible completions:
dir Traffic direction of source interface to mirror from.
mac-fiIter
net-interface Select a NET interface to mirror packet flows from
Nmi-interface Select an NNI interface to mirror packet flows from.
pon-interface Select a PON interface to mirror packet flows from
target Select an NNI interface as mirror-to target (CPU is used if target is not selected).
vlan VLAN ID or 'any' for untagged/mixed traffic.
MDSl-ESUA#_
|
- The next step will enable packets in both directions on net-interface NET1 and display the available completions of the target action.
- From the MDS1-ESUA# command line, input tolt diagnostics flowmirror enable dir both net-interface NET1 target?, and press Enter. Output similar to the following is displayed:
MDS1-ESUA# tolt diagnostics flowmirror enable dir both net-interface NET1 target ? <enter> Possible completions: Description: Select an NNI interface as mirror-to target(CPU is used if target is not selected). QSFPl-2-1 QSFPl-2-2 QSFPl-2-3 QSFPl-2-4 QSFPl-2-5 QSFPl-2-6 SFPl-1-1 SFPl-1-2 SFPl-1-3 SFPl-1-4 MDS1-ESUA# _
Note: Should no target be selected, the system will default the target as the cpu (eth2)
- The next step will enable packets in both directions on net-interface NET1 and capture all the vlans.
The following are the caprure options. Only one can be used at a time.- net-interface – will capture all the vlan packets
- nni-interface – will capture packets a single uplink port
- pon-interface – will capture what packets are going up and down the pon.
- From the MDS1-ESUA# command line, input tolt diagnostics flowmirror enable dir both net-interface NET1 vlan any, and press Enter. Output similar to the following is displayed:
MDS1-ESUA# tolt diagnostics flowmirror enable dir both net-interface NET1 vlan any <enter> Action success true reason MDS1-ESUA# _ - Success true, validates that the flowmirror is running with all traffic on the selected uplink going to the cpu.
- Now that the flowmirror is set up, we will enable rpcap.
- From the MDS1-ESUA# command line, input tolt diagnostics rpcap enable, and press Enter. Output similar to the following is displayed:
MDS1-ESUA# tolt diagnostics rpcap enable <enter> Action success true reason MDS1-ESUA# _ - The next steps will use Wireshark on a remote computer to view the captured packets.
- Click on an interface to display the Capture Options.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy80MTcwMy81NDk1Mi9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNi9pbWFnZSgyMykucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzg5MTAyMzU3fX19XX0_&Signature=Xjbt4aBh9goJZpCXDV5vP-5RMfxxcJmh1cbyO7O~gcIysIcyvVTa7JTNXE5hOwnzM5hOFDhM01ZnsSk0F4u8hG8ezCc1LgCJqt7NwoTRJy3c1g2663n7F50A4kYGi03gMxAKScHGubCP~Cw5c9rK34wAz0xPuXXKEfOIeLQ2x3N~IX6ICRE2tei2-ItJrfwbBLdQPmZUJyew461LEZijp~gbrgQNB2eRkBUFJR96fUDo~nRgf1zdQuJuo2PAeWK-0Q6G6mUG2zbzFO~BI~UbmyKYV1nKBcJA-6DIeU9J85oZoU47s8UNy38EM2zhqXU5s7IS5~EOuJsgoHzHQbod7Q__&Key-Pair-Id=K2TK3EG287XSFC)
- Click on the Manage Interfaces button to access Remote Interfaces.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy80MTcwMy81NDk1Mi9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNi9pbWFnZSgyNCkucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzg5MTAyMzU3fX19XX0_&Signature=gvvJ6LCPxu64rdZw~6eLrXZcH09Fb8yYluA8CHecifyA8uiYUY8fghr84VXlvq7yChAkXSnK7X2eMTb~AyD5CsxT8x6gcGrp2nexOOMMa0xV~Nl219I88JWROznUeEWGNSqp9WSR5LEJWZ1l0jYgx1AVcl5HkAShBHz-AN12-8Lbdemh~~3Ttt-t3yr27Ts6rrMEvAuIbE4vzunb3h~bgNSSpcNc4oyiNjhFRwhsK-a5d8epPsDrKBmsWfISYK94X-uNJpr1d66kK~R5ArGI3YTHFgo5WLs3hueLkbacPKy3wZsJP6LiA-IGwyZ5YVqMlJC7B7jxGT6~zLBYNzk~ig__&Key-Pair-Id=K2TK3EG287XSFC)
- Click on the Remote Interfaces button to add an interface.
. - Add an interface.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy80MTcwMy81NDk1Mi9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNi9pbWFnZSgxNikucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzg5MTAyMzU3fX19XX0_&Signature=Zfu1YNmuoVIU9ltZsCIlcRdYGDJpg-HO1XCmPwRLM27lhSg2FLRorYJwmD84mOkAYHdBuGp3FMm7Yp0gCj46uXaIp1sQk0phtMCbvNw-7p8CWE6OELdp3VrP~VU3KX8I7v~aTowuaSbhcy1OYUSi~Y1VpzjbpOlrI4MXjIE79tQLX2Rj6pE~05EUfcyQ5NaU8NEpkDne9yNxihdgAO4LjvST3XUfC8pu4zms55KT~BMwGySdE7v9IlcngLhdOAu4NDHCSNWHw4EvLNTYHF1wHaVm3T41cFqkLARxz5WhT9xvh5aQQtErdPN8MNQyMv-wVMXsZlBC4ouRcvtVv5LriA__&Key-Pair-Id=K2TK3EG287XSFC)
- Add the IP address of the Host. In this case, it will be the IP address of the OLT (i.e. 172.29.122.141).
- The port number will be the default Wireshark port of 2002.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy80MTcwMy81NDk1Mi9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNi9pbWFnZSgxNykucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzg5MTAyMzU3fX19XX0_&Signature=o1VPDPv~bG~8YzcDksv5ggiiO7Lo~2wwr04N~36o3eOu3rOmFuEqtAeImR9JslAPfhjcGKw5rxatPqdvF9aeqQ8HzB06~~IIHZY5yVtB6E1DiOxyG5L4LKXBFaUmCvwow3e3m-QYT38p1UYonL5JerZYP7Jyb4XtpBYkqdNJ1RAeM3Hu1RMJk0U17e0c2eV1Q~XVSAaGOaZGcWARaSIkxLrMoXJr8nzZ5iup~jy1Udjq0qbBGZ3CW-d1h7OZukgYm3knUHIyQvyzD458Dh1o-OIjKIbVyinHpZPlEvAWkCXNakg~6sfFp1yGxRKs1wF35GvSfcrAAYk-PrybWZkXAA__&Key-Pair-Id=K2TK3EG287XSFC)
- There will be a short delay while Wireshark connects to the OLT, then all the interfaces are displayed.
- We will want to click on eth2 (cpu), which is our mirror target, then select the OK button.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy80MTcwMy81NDk1Mi9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNi9pbWFnZSgxOCkucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzg5MTAyMzU3fX19XX0_&Signature=ksHtGI-YjvDxJ8W-rVBfH66MlzX123X7UIVHNZGhn9qTtNIwypE6~d8rNxfokhIGiYO6l2OnyumCOPVJ4SUnyASFTHIR4dflI1F7QyrUuW6-1XrNfd8nsosYTGn2-0agDHuUOn9xU1VACnle8u47U8z640ASEtkJDaaw7eW0V2mxg~ri-HFwBN62LzHNqUm7GSNhWemAU1cex1SoyNTFljHKPDed1VsLIJ5bpDvJEBjhjgNlaZwTdvxGqMPcwrgOheDVJn9LPFH3HiVcKs14BUzjYibmpS7bVPX~9DZW1P5qCAw1H7l3xPooZJMrnIN00FP8T4sezLUSpN342EQrEQ__&Key-Pair-Id=K2TK3EG287XSFC)
- The next screen will display the available interfaces. Scroll down to display eth2 and double-click to access live captures of the uplink.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy80MTcwMy81NDk1Mi9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNi9pbWFnZSgxOSkucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzg5MTAyMzU3fX19XX0_&Signature=ZIAsH56D0vd8CPr4KZV98cimHOlzMp9gKktyDyb7ZbR~ow9qaI0beyEOGEzVHcm-6Vh~oQH458oM9SgDKSltL4fwrezyheNUaD0bKxw6w0sufj35d88YF7s9SHDTQygpMXTzNkTxHj7UUGodPhgdbSwKd4egXnP59xqwXomR0Um3tJgr1-AWpjzsGS9wo6NouSGgeCQ3i2domB~Vfk5sYKO5kCiN1oUzPwAFtksWyxMDlclW-5jDqDc6xkkXmGyDPrrpURSCCSwplOQIBSSaWTclSBuRZbL6a-rdc51XXumDMcbm0CzdAhkdUO8LmSALzdAfrtNHga2rTlvVbnvR7w__&Key-Pair-Id=K2TK3EG287XSFC)
- We are now getting live captures of our uplink.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy80MTcwMy81NDk1Mi9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNi9pbWFnZSgyMCkucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzg5MTAyMzU3fX19XX0_&Signature=di6yAWtx~dOZ4VzPndw-OH2dQx9j-bNwjmcqRHnXdGVNPY~yZa0PfKumgzm8SMIUcZ9KsCeK1x6qk0-G73UYrWWfFHlhMCL7z6jykJQl1iQzmtXk11vnDDhABsDbCHeiIyr6z76CM3~ThhcoYuwsZVYhGUDw8xtTnYSeDijFkRWGVQHoT9lmnOY96nTziBClcAef0hRZ35qGHdJgFrErtawyWHgKjrxbxavXxTUrG4w7oaUnw4dY0QwqKXrL7-owa4B-EfVaR0~Hzw~W3ouJ3DA5K9QZArB38u~hcVqXvUQzqbyYLyA9biaSGmCXEMcFNUD2IeRRsB0efF7aIJktWQ__&Key-Pair-Id=K2TK3EG287XSFC)
- We will now validate the connection by pinging the OLT by going to the command screen and ping our gateway.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy80MTcwMy81NDk1Mi9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNi9pbWFnZSgyMSkucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzg5MTAyMzU3fX19XX0_&Signature=izoI9000XvSI7BuZhWKRWK8adULjr~svHVzdC8UTWgFn1R~lb0MSQA7xJt6VYO4bubxhzOw7cQAZY1ltPGgbOM3CKv38~yyCd1pOu7TfFeWpEeB3vQ6lKXj6105UoPEl32TPPJdqWJYh3svpp263AcjkSjn7DHXQ0~jLvkH5c0fechh4RU7emuqoNosDI-04PYliwCfzEt~ht87Fts2RLo1ef-Z1liqaYB6vvzDvj49yLpcnfBht4XFMNwBK0vwTuBck68bDr~Yi07lSwXd8iJUhG5O9YprmejCdm6R3zPgBEz0cK3pnT3NVw7XgtnGcz71OFcfWIFWxG~HNSxc0qg__&Key-Pair-Id=K2TK3EG287XSFC)
- On Wireshark the display screen will display, in real time, the ping activity.
.png?Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cHM6Ly9kemY4dnF2MjRlcWhnLmNsb3VkZnJvbnQubmV0L3VzZXJmaWxlcy80MTcwMy81NDk1Mi9ja2ZpbmRlci9pbWFnZXMvcXUvMjAyNi9pbWFnZSgyMikucG5nIiwiQ29uZGl0aW9uIjp7IkRhdGVMZXNzVGhhbiI6eyJBV1M6RXBvY2hUaW1lIjoxNzg5MTAyMzU3fX19XX0_&Signature=ZJElmXC-3qRIMWmSjRd-ckR8Lx6TKUHvW7V--ACrZWqN6RiTSt-1m4zuDpZT4eHaQT23JqaoSmtTx~od7F5pPRPh3G7mgvIasYIP5OB5zRFuvFpuk69RFY4XP7VM9X8ZuTHhFvTJn6JqCT1vcwF1bFdqSsegmtzqZzmPoCOmRi4xor8FkHqxbkeLIaOjCffzQcJTS0VYA0YgwrdK3SFCWW1wpnj8SH25voj1m8wplg5QubNAWx7iFl8uqZYYWU6IdttaKJq6YArMgdXAAuxqzBFh9k~JY-fRqWP6GgFAfYFsZAoxeD8y3dR3Y07Qm3JXU~MxtYYAWrt-FKhsoOn94Q__&Key-Pair-Id=K2TK3EG287XSFC)
- When the session is complete, we will disable the rpcap and the flowmirror.
Note: Should the rpcap and flowmirror remain running, it will slow down the cpu and introduce unnecessary heat to the system.
- From the MDS1-ESUA# command line, input tolt diagnostics rpcap disable, and press Enter. Output similar to the following is displayed.
MDS1-ESUA# tolt diagnostics rpcap disable <enter>
action-success true
reason
MDS1-ESUA# _
|
- From the MDS1-ESUA# command line, input tolt diagnostics flowmirror disable, and press Enter. Output similar to the following is displayed.
MDS1-ESUA# tolt diagnostics flowmirror disable <enter>
action-success true
reason
MDS1-ESUA# _
|
- Session complete
FEEDBACK: Are you happy with this material?
Thank you Your feedback helps us to continually improve our content.