Nortel Networks NN46110-602 manual Viewing a Pcap file with Sniffer Pro, Global IP capture

Models: NN46110-602

1 230
Download 230 pages 7.59 Kb
Page 127
Image 127

Chapter 5 Packet capture 127

6Enter the password that you entered when you enabled packet capture (see “Enabling packet capture on a VPN Router” on page 111).

Note: If you plan to use Sniffer Pro to view the capture file, go to the next section, “Viewing a PCAP file with Sniffer Pro” on page 127.

7From the open Ethereal window, disable Enable network name resolution.

If this parameter is enabled, a large PCAP file takes a long time to open because every address captured tries to perform name address resolution.

8Open the packet capture file (for example, ethernet.cap).

Viewing a PCAP file with Sniffer Pro

Because Sniffer Pro is not free shareware, it is assumed that you have already installed the software on the PC. To view a VPN Router PCAP file with Sniffer Pro:

1Install Ethereal software (see “Installing Ethereal software” on page 125).

2Save the packet capture file and download it to the PC as described in steps 1-6 of “Saving, downloading, and viewing PCAP files” on page 126.

3Open a new DOS window and change directory to the c:\Program Files\Ethereal directory to access the editcap command.

4Run the editcap command so that Sniffer Pro can view the capture. If the capture was done on an Ethernet interface or on a tunnel, type the extension

.enc; if the capture was on done on WAN interface, type the extension .syc. Following are sample commands.

Ethernet interface capture:

editcap -F ngsniffer d:\pcap\ether.cap ether1.enc

IPsec tunnel capture:

editcap -T ether -F ngsniffer d:\pcap\ipsec.cap ipsec.enc

Global IP capture:

editcap -T ether -F ngsniffer d:\pcap\rawip.cap rawip.enc

Nortel VPN Router Troubleshooting

Page 127
Image 127
Nortel Networks NN46110-602 manual Viewing a Pcap file with Sniffer Pro, Global IP capture