Cace Technologies Ultimate Guide to Using AirPcap Adapters for Wireless Capture

Page 21

WEP keys are array of bytes of arbitrary length expressed in hexadecimal.

WPA and WPA2 keys can be of two types:

Passphrase (WPA-PWD): This is the Passprase and SSID combination most often used to configure WPA and WPA2. The passphrase is a string between 8 and 63 characters in length. The SSID can be omitted, in which case Wireshark will use the last- seen SSID on the network. Non-printable characters can be represented by a “%” character followed by a hexadecimal number for both the passphrase and SSID. The passphrase and SSID are used to derive Pre-Shared Key.

Pre-Shared key (WPA-PSK): This allows the user to provide a binary TKIP or CCMP key (used to derive the temporary key of each session) which is normally the kind of key returned by tools like Aircrack. The key is 256 bit long, and is expressed as a hex string (64 characters). A tool to convert a passphrase and SSID into a 256-bit PSK can be found on the Wireshark web site at http://www.wireshark.org/tools/wpa-psk.html.

The keys that you specify in this list are global. Every AirPcap adapter, included the Multi-Channel Aggregator, will use them.

The Multi-Channel Aggregator (applies to USB AirPcap adapters only)

The Multi-Channel Aggregator has its own FCS Filter, Capture Type and option to Include 802.11 FCS in Frames. These settings, and not the ones of the physical adapter, will be used by when capturing from the Multi- Channel Aggregator.

However, it’s not possible to set the channel of the Multi-Channel Aggregator; instead, the channel drop-down box will show the list of the aggregated channels. Multichannel aggregation is not available with the AirPcap N Cardbus adapter.

To change the channel of any individual adapter, select the

CaptureOptions menu item, select the desired interface, click on the Wireless Settings button and then set the channel value in the channel drop-down box.

AirPcap User’s Guide

19

Image 21
Contents Family of Wireless Capture Adapters User’s Guide Copyrights Contents and Figures Figures AirPcap AirPcap Tx AirPcap Ex AirPcap N AirPcap Product FamilyBrief Introduction to TerminologyStandards Channels Types of Frames Http//standards.ieee.org/getieee802/802.11.html How AirPcap Adapters OperateMultiple Channel Capture applies to USB adapters only Identifying the AirPcap Adapters Configuring the Adapters the AirPcap Control PanelAirPcap N and Extension ChannelSetting SettingsWEP Keys List improves performance Multi-Channel Aggregator AirPcap and Wireshark Identifying the AirPcap Adapters in WiresharkWireless Toolbar Wireless toolbar has the following controls Wireless Settings Dialog Parameters that can be configured are Decryption Keys Management Dialog Decryption Keys Management Dialog in WiresharkAirPcap User’s Guide Transmit Raw 802.11 Frames on Your Network Where to Learn More 4GHz Band Appendix a 802.11 Frequencies5GHz Band Channels Supported by the AirPcap Product FamilyAirPcap N

AirPcap Wireless Capture Adapters specifications

Cace Technologies AirPcap Wireless Capture Adapters are essential tools for network professionals aiming to monitor, analyze, and troubleshoot wireless networks. These innovative devices enable packet capture and analysis over 802.11 wireless networks, providing insights that are crucial for maintaining network integrity and performance.

One of the main features of AirPcap adapters is their ability to capture raw 802.11 packets in real time, including management, control, and data frames. This capability allows for a comprehensive view of wireless communications, assisting engineers in identifying issues like signal interference, unauthorized access points, and potential security breaches.

Another significant characteristic is the support for both 802.11a/b/g/n standards. This wide-ranging compatibility ensures that users can effectively analyze traffic across various network types, regardless of the generation of equipment being utilized. Additionally, AirPcap adapters are equipped with advanced features like packet injection, which is beneficial for testing network robustness and security defenses.

The wireless capture adapters are often praised for their seamless integration with popular analysis tools such as Wireshark. This combination provides users with a powerful interface for performing in-depth packet analysis, enabling the decoding of complex protocols and offering visualizations that aid in understanding network behaviors.

For ease of use, AirPcap adapters come equipped with a compact design and user-friendly software. They can be connected to laptops or portable devices, making them ideal for field use. Their portability ensures that field technicians or network analysts can perform assessments in various environments without the need for extensive setup or configurations.

Security is another critical aspect where AirPcap shines. These adapters allow for the capture of encrypted packets, provided the user has the appropriate decryption keys. This feature is particularly valuable for troubleshooting security protocols and ensuring that data transmitted over the network is secure.

In conclusion, Cace Technologies AirPcap Wireless Capture Adapters are versatile and powerful tools for any network engineer or security professional. With their ability to capture and analyze a wide range of wireless traffic, their compatibility with industry-standard tools, and their advanced features, AirPcap adapters are indispensable in today's increasingly wireless world. Whether used for routine monitoring, troubleshooting, or security assessments, these adapters offer a robust solution for wireless network management.