On-Box Packet Sniffer
Monitor and capture IPv4 traffic on ingress and egress interfaces with the on-box packet sniffer.
The on-box packet sniffer is a packet monitoring feature that enables you to monitor and capture IPv4 traffic directly on the device. You do not need an external packet analyzer, collector, or monitoring agent.
You can monitor traffic on ingress and egress interfaces and match packets by using attributes such as source IP address, destination IP address, source MAC address, destination MAC address, VLAN ID, and VXLAN network identifier (VNID).
You can use the on-box packet sniffer to monitor the captured packets in real time through the CLI and analyze the packets offline by using packet capture files. You can also view Virtual Extensible LAN (VXLAN) traffic and analyze packet forwarding behavior on the device.
Benefits of On-Box Packet Sniffer
-
Monitor packets in real time through the CLI on an on-demand basis without requiring external monitoring infrastructure.
-
Simplify troubleshooting by enabling packet monitoring and traffic analysis directly on the device.
-
Validate packet forwarding behavior and verify packet attributes during troubleshooting.
Limitations
-
With the on-box packet sniffer, you cannot:
-
Monitor host-generated packets, IPv6 packets, logical interfaces (IFLs), integrated routing and bridging (IRB) interfaces, and interface ranges.
-
Include a prefix when you specify an IPv4 address in the CLI.
-
Run concurrent packet capture sessions.
-
Match packets using the priority VLAN (VLAN 0) attribute.
-
Combine the attributes VNID, source IP address, and destination IP address for packet monitoring.
-
Combine the Layer 2 (L2) and Layer 3 (L3) attributes in the same packet-matching filter. If you specify attributes from both the layers, the on-box packet sniffer uses the L2 attributes.
-
-
Packet monitoring on an aggregated Ethernet interface (aex) requires specifying a member interface rather than the aggregated Ethernet interface.
-
Packet monitoring based on an inner source MAC address or inner destination MAC address requires a byte offset. With a UDF filter, the on-box packet sniffer matches up to 32 consecutive bits within a 48-bit MAC address. The
byte-offsetoption in themonitor pfe traffic interfacecommand specifies which 32 bits of the MAC address to match.
Monitor Traffic on an Egress Interface
To monitor traffic on an egress interface:
Configure a Packet Forwarding Engine trace file to store trace logging information during packet monitoring:
set services pfe traffic traceoptions file filename
Configure an unused interface as a loopback interface (lo0). Specify this interface as the egress interface for packet monitoring.
set interface interface-name ether-options loopback
Example:
set interfaces xe-0/0/2 ether-options loopback
(Optional) Configure the packet-monitoring duration:
set services pfe traffic monitor-timer time
By default, packet monitoring runs for 5 minutes. You can configure the monitoring duration for up to 60 minutes.
Commit the configuration:
commit
Start packet monitoring by using the
monitor pfe traffic interfacecommand. Specify theegressoption, theegress-interface, and one or more packet-matching attributes.Note:You must specify at least one packet-matching attribute to start packet monitoring.
Example:
monitor pfe traffic interface xe-0/0/1 egress egress-interface xe-0/0/2 vlan-id 100
In this example:
xe-0/0/1is the interface you monitor for egress traffic.xe-0/0/2is the loopback interface used for egress packet capture.vlan-id 100is the packet-matching attribute used to filter the traffic for packet monitoring.
View captured packets in real time through the CLI or save captured packets in packet capture files for offline analysis.
monitor pfe traffic interface xe-0/0/1 egress egress-interface xe-0/0/2 vlan-id 100 write-file /var/tmp/capture.pcap
Manually delete packet capture files after you complete troubleshooting.
Monitor Traffic on an Ingress Interface
To monitor traffic on an ingress interface:
Configure a Packet Forwarding Engine trace file to store trace logging information during packet monitoring:
set services pfe traffic traceoptions file filename
(Optional) Configure the packet-monitoring duration:
set services pfe traffic monitor-timer time
By default, packet monitoring runs for 5 minutes. You can configure the monitoring duration for up to 60 minutes.
Commit the configuration:
commit
Start packet monitoring by using the
monitor pfe traffic interfacecommand and specify theingressoption along with one or more packet-matching attributes.Note:You must specify at least one packet-matching attribute to start packet monitoring.
Example:
monitor pfe traffic interface xe-0/0/1 ingress outer-dmac 00:00:00:00:00:0b
In this example:
xe-0/0/1is the interface you monitor for ingress traffic.outer-dmac 00:00:00:00:00:0bis the packet-matching attribute used to filter the traffic for packet monitoring.
View captured packets in real time through the CLI or save captured packets in packet capture files for offline analysis.
monitor pfe traffic interface xe-0/0/1 ingress outer-dmac 00:00:00:00:00:0b write-file /var/tmp/capture.pcap
Manually delete packet capture files after you complete troubleshooting.