Welcome to Infoblox NetMRI Community Sign in | Join | Help
in Search

Terry's Blog

RSS Feed

Cisco IOS 12.4(20)T Packet Capture Feature

Jamey Heary, CCIE No. 7680, who writes for Network World's Cisco Subnet, recently wrote about a set of new features in Cisco's IOS 12.4(20)T release.  One of the features he describes is pretty neat:   Packet Capture.

At times, the only way you can troubleshoot a network problem is to get a packet capture of some application or of the traffic on a suspect link.  So you need to take your packet analyzer out to the site and capture data for this analysis.  Distributed Sniffer and similar systems were created to allow network engineers to not always have to go into the field to capture data.  With technologies like MPLS, remote sites will often communicate with one another without the data transiting a central facility where an expensive packet capture probe can be located.

So Cisco's new feature that allows packet capture within the router will help the network engineer perform diagnosis and analysis without having to go onsite.  Also cool is the fact that this packet capture supports both CEF and process switched packets. One of the neat features is that the packet capture data is exportable in PCAP format, so analysis tools like Wireshark can import the capture data.

 As with any new feature, it is only available on a subset of routers - the ISR and 7200 series routers, which are software based.  I'm sure that the hardware based routers will follow in the future as new ASICs support packet capture.

 Take a look at Jamey's article and its links to the relevant documentation for details on how it works.

  -Terry
 

 

Comments

No Comments

About tslattery

Terry Slattery, CCIE #1026, is a senior network engineer with decades of experience in the internetworking industry. Prior to joining Chesapeake NetCraftsmen as a full time consultant, Terry was the founder and CTO of Netcordia, and inventor of NetMRI, a suite of network management products. Terry started Netcordia as a consulting company in 2000 and transitioned to a network management product company in 2003. During the consulting days, he used his network design and implementation skills to lead a team in the design and implementation of a high availability network at a brokerage clearing house. Terry is the former President and founder of Chesapeake Computer Consultants, Inc., a networking and computer systems training and consulting company. He co-invented and patented the vLab(tm) internet-based remote lab system. He is co-author of the McGraw Hill text Advanced IP Routing in Cisco Networks. Terry led the team that developed the current Cisco IOS user interface under contract to Cisco Systems. Terry is experienced in the design and installation of large TCP/IP based networks and is a successful network protocol instructor. He is the second Cisco Certified Internetworking Expert (CCIE) #1026 and the first outside of Cisco. He enjoys membership on the Vanderbilt University Engineering School’s Industrial Advisory Board and the IEEE.

This Blog

Syndication