cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4674
Views
10
Helpful
7
Replies

Packet capture in 1841 Router

hclisschennai
Level 1
Level 1

Hi All,

I have CISCO 1841 Router. It is working perfectly.

I want to see / capture all the packets passing through / processed by the Router. I want to see the payload and details of the traffic.

I tried to take the logs. I am getting only the events happening in the firewall like source / destination address details, but not the payload. I want to capture these traffic and analyse it using protocol analyzer tools like Ethereal / Wireshark.

I am able to do this in ASA firewall using "capture" command. How to achieve this in Cisco Router

Kindly help me.

regards,

R.B.Kumar

7 Replies 7

Richard Burts
Hall of Fame
Hall of Fame

R.B.Kumar

It is very nice that the ASA has this capability. However the ASA is a very different OS from the 1841 router. I am not aware of any way to do a similar function on the 1841.

HTH

Rick

HTH

Rick

Hi,

Any way is it possible to do this in Cisco Switches

R.B.Kumar

Hi Kumar,

You can create a SPAN port on the Cisco switch with monitor session command and then use Wireshark to capture it. Cisco routers and switches do not have the capture feature like the FW's.

HTH,

jerry

Hi Jerry,

I am going through Cisco Literatures and found two methods of doing packet capture in Routers.

Method 1: traffic-export

Method 2: EPC ( Embedded Packet Capturing)

Do you any comment on this.?

What is the difference between these two?

R.B.Kumar

Hi Kumar,

I have not use these feature. Just reading something off CCO - EPC is for the 7200 platform and only available to IOS 12.4(20)T or beyond.

However, traffic-export is an older feature. The concept of traffic-export is similar to netflow-export, where it required an external decoder/sniffer. I would think that monitoring the CPU utilization is a good idea when first turned on these features.

http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_ip_traff_export_ps6350_TSD_Products_Configuration_Guide_Chapter.html

HTH,

jerry

Mark Yeates
Level 7
Level 7

R.B.Kumar

You could give IP Traffic Export Packet Capture at try. I have not used or tested this feature yet, but this may help.

http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/ht_rawip.html#wp1051438

HTH,

Mark

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card