cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
287
Views
0
Helpful
1
Replies

Displaying client tcp traffic

Mr. Bash
Level 1
Level 1

I want to see what my associated users are connecting to [ip address] and what tcp port.

I see a command that is close to what I'm looking for....show tcp brief. This is what I get:

TCB Local Address Foreign Address (state)

00B1063C 10.1.1.15.23 laptop.am.4823 ESTAB

[This shows my laptop hitting the AP on port 23.]

The problem is that this is from the AP perspective, I'm looking for connection details from a user perspective.

Does anyone know if this is possible and if so what command would accomplish this?

1 Reply 1

ericgarnel
Level 7
Level 7

You will want to look into netflow

there are several commercial apps that do this as well as open source apps such as ntop.

You can also get such info along with even more detail using sniffer software.

The cisco wireless system has the ability to feed a sniffer app from the wireless directly.

if you are using 4.x wlc, you can feed it to airopeek, if you are using 5.x & above, you can point it at wireshark

http://www.cisco.com/en/US/docs/wireless/controller/4.2/command/reference/cli42c1.html#wp2465366

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: