ON THIS PAGE
Capture Packets from Transit Traffic
Learn how to capture packets from transit traffic on your MX204, MX301, MX304, MX10004, or MX10008 router.
To capture transit traffic on a Juniper MX router, use port-mirroring (via firewall
filters) or the packet-capture feature to send traffic to the Routing Engine for analysis.
The monitor traffic interface command only captures traffic destined
to or from the Routing Engine.
To capture transit traffic across the network, use one of the following methods:
- Port mirroring (recommended for production): Configure a firewall filter to
match specific transit traffic and mirror it to a monitoring port or an analyzer.
- Define a
samplinginstance inforwarding-options, set the input interface.
- Define a
- On-box packet sniffer (for short-term analysis): Use the operational command
request packet-capture startto capture packets to a PCAP file without needing a commit. - Inline flow monitoring: Use traffic sampling to capture and save packets to the hard disk based on interface, protocol, or IP address.
For more information on capturing transit traffic on a Junos OS device, see the Network Management and Monitoring Guide.
- Transit traffic is not captured by
monitor traffic interface. - Ensure the router has an Internet Processor II ASIC (standard on MX) for proper sampling.
- The
monitor traffic interfacecommand can be used to verify on-box sniffing.
Traffic Sampling
Traffic sampling redirects sampled traffic to the Routing Engine to be saved as a
.pcapfile.
-
Define the capture file and settings.
set forwarding-options packet-capture file filename interface-ge-0-0-0.pcap set forwarding-options packet-capture maximum-capture-size 1500
-
Define what specific traffic you want to capture and set the action to
sample.set firewall family inet filter PCAP_FILTER term 1 from source-address 192.168.1.100 set firewall family inet filter PCAP_FILTER term 1 then sample set firewall family inet filter PCAP_FILTER term 2 then accept
-
Enable sampling in 'forwarding options'.
set forwarding-options sampling input rate 1 set forwarding-options sampling family inet output file filename interface ge-0-0-0.pcap
Port Mirroring
Use the port mirroring method if you want to send a copy of all transit traffic on a port to an external device for analysis.
Configure the analyzer.
set forwarding-options analyzer PCAP_MIRROR input ingress interface <transit_port> set forwarding-options analyzer PCAP_MIRROR output interface <destination_port>
Analyze the capture.
Captured files are typically stored in
/var/tmp/.View the file on the router using
monitor traffic read-file /var/tmp/ge-0-0-0.pcap.