EasyManuals Logo

Cisco Catalyst 4500 Series Configuration Guide

Cisco Catalyst 4500 Series
1610 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #1303 background imageLoading...
Page #1303 background image
56-7
Software Configuration Guide—Release IOS XE 3.3.0SG and IOS 15.1(1)SG
OL-25340-01
Chapter 56 Configuring Wireshark
Configuring Wireshark
• Redirection features—In the input direction, features traffic redirected by Layer 3 (such as PBR and
WCCP), are logically later than Layer 3 Wireshark attachment points. Wireshark captures these
packets even though they might later be redirected out another Layer 3 interface. Symmetrically,
output features redirected by Layer 3 (such as egress WCCP) are logically prior to Layer 3
Wireshark attachment points, and Wireshark will not capture them.
• Classification copy features—Features that generate copies of packets from the role-based and
Security lookup types are compatible with Wireshark. Multiple copies of these packets are
generated.
• SPAN—Wireshark and SPAN sources are compatible. You can configure an interface as a SPAN
source and as a Wireshark attachment point simultaneously. Configuring a SPAN destination port
as a Wireshark attachment point is not supported.
There are four classification results for input and output classification. In the input direction, they are
ordered role-based, security, QoS, and forwarding override. In the output direction they are ordered
forwarding override, role-based, security, and QoS.
On the input side, the Wireshark capture feature is placed in the forwarding override result type,
prioritized above the other FO features (such as multicast local source capture, PBR and ingress WCCP).
The packets captured by Wireshark are before any redirection by PBR or WCCP. Because security ACLs
are applied ahead of FO-related features, packets that are dropped by security ACLs are not captured by
Wireshark.
On the output side, the Wireshark capture feature is placed in the forwarding override result type,
prioritized below the other FO features (such as egress WCCP). Wireshark captures packets only if the
other egress FO features do not apply.
Configuring Wireshark
The CLI for configuring Wireshark requires that the feature be executed only from EXEC mode. Actions
that usually occur in configuration submode (such as defining capture points), are handled at the EXEC
mode instead. All key commands are not NVGEN’d and are not synchronized to the standby supervisor
in NSF and SSO scenarios.
The following sections describe how to configure Wireshark:
• Default Wireshark Configuration, page 56-7
• Wireshark Configuration Guidelines, page 56-8
• Defining, Modifying, or Deleting a Capture Point, page 56-8
• Activating and Deactivating a Capture Point, page 56-10
Default Wireshark Configuration
Table 56-1 shows the default Wireshark configuration.
Table 56-1 Default Wireshark Configuration
Feature Default Setting
Duration No limit
Packets No limit
Packet-length No limit (full packet)

Table of Contents

Other manuals for Cisco Catalyst 4500 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco Catalyst 4500 Series and is the answer not in the manual?

Cisco Catalyst 4500 Series Specifications

General IconGeneral
SeriesCatalyst 4500 Series
CategorySwitch
Layer SupportLayer 2, Layer 3
Form FactorModular chassis
StackableNo
Chassis Slots3, 6, 7, 10
Power Supply OptionsAC, DC
RedundancyPower supply, Supervisor engine
Network ManagementCisco IOS Software CLI, SNMP, Cisco Prime Infrastructure
FeaturesSecurity, QoS
Port DensityUp to 384 ports per chassis
Security Features802.1X, ACLs, DHCP Snooping, Dynamic ARP Inspection, IP Source Guard
Supervisor Engine8-E

Related product manuals