cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Join Customer Connection to register!
310
Views
0
Helpful
3
Replies
dcarr3311
Beginner

packet capture Nexus 56128

Hi 

I'm troubleshooting a problem with a host connected to my Nexus 56128. I would like to do a packet capture of the data going to that host. Is there an easy way to grap a .pcap file of this data from the switch? 

 

thanks 

Dan 

3 REPLIES 3
balaji.bandi
VIP Expert

you can use local tool inside switch to capture.

 

https://www.cisco.com/c/en/us/support/docs/switches/nexus-5000-series-switches/116201-technote-ethanalyzer-00.html



BB


*** Rate All Helpful Responses ***

Hi Balaji!

 

it appears that you can only capture control plane data with that tool. What I want to do is capture packets on the data plane from host to host. 

 

Any thoughts on that? 

 

Thanks 

Dan 

Hey Dan,

 

You have 2 ways to accomplish this, the first is a classic monitor session where you mirror the traffic from one port(so the one where you host is connected) to a second port where you might have a sniffer attached(e.g a PC with wireshark running, or a linux box with tcpdump).

The second option is to use ELAM, this will not give you the full picture on the packets passing though as it will capture only a specific subset of traffic previously defined by a trigger with a filter.

 

You can find more details on ELAM here:

https://clnv.s3.amazonaws.com/2015/usa/pdf/BRKDCT-3100.pdf

 

and on SPAN/monitor session here:

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5600/sw/system_management/7x/b_5600_System_Mgmt_Config_7x/b_6k_System_Mgmt_Config_7x_chapter_01110.html

 

HTH,

ADP