Administration

3

 

Packet Capture

 

 

 

 

 

All traffic to and from a specific client: wlan.addr == 00:00:e8:4e:5f:8e

In remote capture mode, traffic is sent to the computer running Wireshark through one of the network interfaces. Depending on the location of the Wireshark tool, the traffic can be sent on an Ethernet interface or one of the radios. To avoid a traffic flood caused by tracing the packets, the WAP device automatically installs a capture filter to filter out all packets destined to the Wireshark application. For example, if the Wireshark IP port is configured to be 58000, then this capture filter is automatically installed on the WAP device:

not portrange 58000-58004

Due to performance and security issues, the packet capture mode is not saved in NVRAM on the WAP device; if the WAP device resets, the capture mode is disabled and then you must reenable it to resume capturing traffic. Packet capture parameters (other than mode) are saved in NVRAM.

Enabling the packet capture feature can create a security issue: Unauthorized clients may be able to connect to the WAP device and trace user data. The performance of the WAP device also is negatively impacted during packet capture, and this impact continues to a lesser extent even when there is no active Wireshark session. To minimize the performance impact on the WAP device during traffic capture, install capture filters to limit which traffic is sent to the Wireshark tool. When capturing 802.11 traffic, a large portion of the captured frames tends to be beacons (typically sent every 100 ms by all APs). Although Wireshark supports a display filter for beacon frames, it does not support a capture filter to prevent the WAP device from forwarding captured beacon packets to the Wireshark tool. To reduce the performance impact of capturing the 802.11 beacons, disable the capture beacons mode.

Packet Capture File Download

You can download a capture file by TFTP to a configured TFTP server, or by HTTP(S) to a computer. A capture is automatically stopped when the capture file download command is triggered.

Because the capture file is located in the RAM file system, it disappears if the WAP device is reset.

To download a packet capture file using TFTP:

Cisco Small Business WAP121 and WAP321 Wireless-N Access Point with PoE

55

Page 57
Image 57
Cisco Systems WAP321, WAP121 manual Packet Capture File Download

WAP121, WAP321 specifications

Cisco Systems has long been recognized for its innovation in networking technologies, and the Cisco WAP321 and WAP121 access points are prime examples of its commitment to delivering reliable, high-performance wireless networking solutions for small and medium-sized businesses. These devices offer a robust set of features designed to meet the requirements of modern wireless networking while ensuring ease of use and deployment.

The Cisco WAP321 is a dual-band access point that operates in both the 2.4 GHz and 5 GHz frequency bands, providing flexibility and improved performance in crowded environments. With support for the 802.11n Wi-Fi standard, it boasts a combined data rate of up to 450 Mbps, enabling high-speed connections for multiple users simultaneously. The WAP321 also includes advanced features such as multiple SSIDs and VLAN support, allowing businesses to segment their networks for enhanced security and management control.

One of the standout characteristics of the WAP321 is its ability to act as a lightweight access point, meaning it can be managed through a Cisco Wireless LAN Controller (WLC) for larger deployments. This capability allows for centralized management of multiple access points, making it easier for IT administrators to deploy, configure, and monitor their network infrastructure.

On the other hand, the Cisco WAP121 is designed for those requiring a simpler, more cost-effective solution. This single-band access point also operates on the 2.4 GHz band but still provides robust performance with wireless speeds reaching up to 300 Mbps. It is ideal for small businesses looking to develop or expand their wireless networks without the complexities associated with more advanced systems.

Both models feature Power over Ethernet (PoE) capability, enabling them to receive power through the Ethernet cable, which simplifies installation and reduces the need for additional power outlets. Additionally, they support advanced security protocols, including WPA/WPA2 encryption, ensuring that sensitive data transmitted over the network remains protected from unauthorized access.

The ease of setup and user-friendly management interfaces of both the WAP321 and WAP121 make them appealing options for businesses lacking extensive IT resources. With features aimed at enhancing both performance and security, these access points represent powerful tools for achieving reliable wireless connectivity in a business environment. Whether organizations opt for the WAP321 for its extensive capabilities or the WAP121 for its simplicity, both access points reflect Cisco's dedication to meeting diverse networking needs.