On-Box Packet Sniffer

Monitor and capture IPv4 traffic on ingress and egress interfaces with the on-box packet sniffer.

The on-box packet sniffer is a packet monitoring feature that enables you to monitor and capture IPv4 traffic directly on the device. You do not need an external packet analyzer, collector, or monitoring agent.

You can monitor traffic on ingress and egress interfaces and match packets by using attributes such as source IP address, destination IP address, source MAC address, destination MAC address, VLAN ID, and VXLAN network identifier (VNID).

You can use the on-box packet sniffer to monitor the captured packets in real time through the CLI and analyze the packets offline by using packet capture files. You can also view Virtual Extensible LAN (VXLAN) traffic and analyze packet forwarding behavior on the device.

Benefits of On-Box Packet Sniffer

  • Monitor packets in real time through the CLI on an on-demand basis without requiring external monitoring infrastructure.

  • Simplify troubleshooting by enabling packet monitoring and traffic analysis directly on the device.

  • Validate packet forwarding behavior and verify packet attributes during troubleshooting.

Limitations

  • With the on-box packet sniffer, you cannot:

    • Monitor host-generated packets, IPv6 packets, logical interfaces (IFLs), integrated routing and bridging (IRB) interfaces, and interface ranges.

    • Include a prefix when you specify an IPv4 address in the CLI.

    • Run concurrent packet capture sessions.

    • Match packets using the priority VLAN (VLAN 0) attribute.

    • Combine the attributes VNID, source IP address, and destination IP address for packet monitoring.

    • Combine the Layer 2 (L2) and Layer 3 (L3) attributes in the same packet-matching filter. If you specify attributes from both the layers, the on-box packet sniffer uses the L2 attributes.

  • Packet monitoring on an aggregated Ethernet interface (aex) requires specifying a member interface rather than the aggregated Ethernet interface.

  • Packet monitoring based on an inner source MAC address or inner destination MAC address requires a byte offset. With a UDF filter, the on-box packet sniffer matches up to 32 consecutive bits within a 48-bit MAC address. The byte-offset option in the monitor pfe traffic interface command specifies which 32 bits of the MAC address to match.

Monitor Traffic on an Egress Interface

To monitor traffic on an egress interface:

  1. Configure a Packet Forwarding Engine trace file to store trace logging information during packet monitoring:

  2. Configure an unused interface as a loopback interface (lo0). Specify this interface as the egress interface for packet monitoring.

    Example:

  3. (Optional) Configure the packet-monitoring duration:

    By default, packet monitoring runs for 5 minutes. You can configure the monitoring duration for up to 60 minutes.

  4. Commit the configuration:

  5. Start packet monitoring by using the monitor pfe traffic interface command. Specify the egress option, the egress-interface, and one or more packet-matching attributes.

    Note:

    You must specify at least one packet-matching attribute to start packet monitoring.

    Example:

    In this example:

    • xe-0/0/1 is the interface you monitor for egress traffic.
    • xe-0/0/2 is the loopback interface used for egress packet capture.
    • vlan-id 100 is the packet-matching attribute used to filter the traffic for packet monitoring.
  6. View captured packets in real time through the CLI or save captured packets in packet capture files for offline analysis.

    Manually delete packet capture files after you complete troubleshooting.

Monitor Traffic on an Ingress Interface

To monitor traffic on an ingress interface:

  1. Configure a Packet Forwarding Engine trace file to store trace logging information during packet monitoring:

  2. (Optional) Configure the packet-monitoring duration:

    By default, packet monitoring runs for 5 minutes. You can configure the monitoring duration for up to 60 minutes.

  3. Commit the configuration:

  4. Start packet monitoring by using the monitor pfe traffic interface command and specify the ingress option along with one or more packet-matching attributes.

    Note:

    You must specify at least one packet-matching attribute to start packet monitoring.

    Example:

    In this example:

    • xe-0/0/1 is the interface you monitor for ingress traffic.
    • outer-dmac 00:00:00:00:00:0b is the packet-matching attribute used to filter the traffic for packet monitoring.
  5. View captured packets in real time through the CLI or save captured packets in packet capture files for offline analysis.

    Manually delete packet capture files after you complete troubleshooting.