<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Onboard Packet Capture SDA in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/onboard-packet-capture-sda/m-p/4606801#M1847</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;The behavior you are seing seems to be expected. As you are using "Embedded Packet Capture", Cisco informs that:&lt;/P&gt;&lt;P&gt;"EPC captures multicast packets only on ingress and does not capture the replicated packets on egress."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you can try is to use "Wireshark" mode on the switch. Ultimately, you can try to run&amp;nbsp;Wireshark on the endpoint, if possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can refer to this guide for more information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/nmgmt/b_169_nmgmt_9300_cg/configuring_packet_capture.html" href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/nmgmt/b_169_nmgmt_9300_cg/configuring_packet_capture.html" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/nmgmt/b_169_nmgmt_9300_cg/configuring_packet_capture.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 May 2022 10:49:42 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2022-05-09T10:49:42Z</dc:date>
    <item>
      <title>Onboard Packet Capture SDA</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/onboard-packet-capture-sda/m-p/4606587#M1846</link>
      <description>&lt;P&gt;Hi SDA-Experts,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;shortly to the environement:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have an SDA Fabric in our Location.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use the Catalyst C9300-48P as Access Switch.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our actual version is the 17.3.4 (which was the recommended at this time)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we recently had a case on our end where we wanted to capture multicast traffic for one of the attached devices.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since it is a quite remote location we wanted to use the onboard capture of the C9300.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;So we added the Trace like this:&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;monitor capture [CapName] file ring 3 size 100 location flash:[CAPNAME].pcap interface [,...] both match any&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But from the capture itself I only see incoming traffic. So from the device to the switch.&amp;nbsp; Everything which is&amp;nbsp;&lt;/P&gt;&lt;P&gt;VXLAN encapsulated to the device is not visible here. We did a workaround to capture the Uplink and decoded VXLAN in the capture. But for switches with high traffic beside the one we want to capture this is not feasible since we get a big load of data that we don't need...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anybody has some tip how to get all the traffic? Or is the only way to do a span session?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 06:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/onboard-packet-capture-sda/m-p/4606587#M1846</guid>
      <dc:creator>Dominik_</dc:creator>
      <dc:date>2022-05-09T06:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Onboard Packet Capture SDA</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/onboard-packet-capture-sda/m-p/4606801#M1847</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;The behavior you are seing seems to be expected. As you are using "Embedded Packet Capture", Cisco informs that:&lt;/P&gt;&lt;P&gt;"EPC captures multicast packets only on ingress and does not capture the replicated packets on egress."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you can try is to use "Wireshark" mode on the switch. Ultimately, you can try to run&amp;nbsp;Wireshark on the endpoint, if possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can refer to this guide for more information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/nmgmt/b_169_nmgmt_9300_cg/configuring_packet_capture.html" href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/nmgmt/b_169_nmgmt_9300_cg/configuring_packet_capture.html" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/nmgmt/b_169_nmgmt_9300_cg/configuring_packet_capture.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 May 2022 10:49:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/onboard-packet-capture-sda/m-p/4606801#M1847</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2022-05-09T10:49:42Z</dc:date>
    </item>
  </channel>
</rss>

