Capture Packets from Transit Traffic

Learn how to capture packets from transit traffic on your MX204, MX301, MX304, MX10004, or MX10008 router.

To capture transit traffic on a Juniper MX router, use port-mirroring (via firewall filters) or the packet-capture feature to send traffic to the Routing Engine for analysis. The monitor traffic interface command only captures traffic destined to or from the Routing Engine.

To capture transit traffic across the network, use one of the following methods:

  • Port mirroring (recommended for production): Configure a firewall filter to match specific transit traffic and mirror it to a monitoring port or an analyzer.
    • Define a sampling instance in forwarding-options, set the input interface.
  • On-box packet sniffer (for short-term analysis): Use the operational command request packet-capture start to capture packets to a PCAP file without needing a commit.
  • Inline flow monitoring: Use traffic sampling to capture and save packets to the hard disk based on interface, protocol, or IP address.

For more information on capturing transit traffic on a Junos OS device, see the Network Management and Monitoring Guide.

Note:
  • Transit traffic is not captured by monitor traffic interface.
  • Ensure the router has an Internet Processor II ASIC (standard on MX) for proper sampling.
  • The monitor traffic interface command can be used to verify on-box sniffing.

Traffic Sampling

Traffic sampling redirects sampled traffic to the Routing Engine to be saved as a .pcapfile.

  1. Define the capture file and settings.

  2. Define what specific traffic you want to capture and set the action to sample.

  3. Enable sampling in 'forwarding options'.

Port Mirroring

Use the port mirroring method if you want to send a copy of all transit traffic on a port to an external device for analysis.

  1. Configure the analyzer.

  2. Analyze the capture.

    • Captured files are typically stored in /var/tmp/.

    • View the file on the router using monitor traffic read-file /var/tmp/ge-0-0-0.pcap.