How can wireless packets be captured from APs managed by a Controller?
Zyxel_Judy
Posts: 1,627 Zyxel Employee
This FAQ applies to Wi-Fi 6 models with firmware versions older than 6.70, Wi-Fi 5 models and small business models such as the NWA50AX, NWA90AX, NWA55AXE, NWA50AX PRO, and NWA90AX PRO.
Scenario
An IT engineer want to monitor wireless traffic to make sure the entire flow when a wireless station connecting to an SSID.
Typology
Prerequisite
- Since the listed Access Point (AP) above cannot capture the wireless frames it transmits, if there is only one AP in the network, an additional AP is required to capture the wireless frames.
- Service AP: This is the AP that needs monitoring.
- Monitor AP: This AP listens and monitors the communication between the Service AP and devices, such as a phone.
- Ensure that both APs are set to the same radio frequency, channel width, and channel to capture packets effectively. For instance, set both APs to use the 5GHz radio frequency, a channel width of 20 MHz, and channel 36. This configuration ensures that the packet capture is comprehensive.
Configuration
In Controller
- Configuration > Object > AP Profile > Radio > Fix the radio, channel width and channel.
- Configuration > Wireless > AP Management > AP Group > Apply SSID and radio for 2 APs.
- Maintenance > Diagnostics > Packet capture > Remote captures > Remote capture > Select the Monitor AP > Click Query > Input Server Port as 2002 and click Start
In the laptop where Wireshark has already installed inside
- Click the “Capture” button on the dashboard, or the gear icon on the menu bar.
- Click “Manage Interfaces” button on the pop-up window.
- Move to the third tab “Remote Interface”, and then click the + plus icon on it.
- Type the IP address of the Monitor AP and the port number (Zyxel set default as port 2002) > Press “OK”
- Select the interface(radiotap0 = 2.4GHz radio interface, radiotap2 = 5GHz radio interface), and then press OK and Start
- Allow the wireless client to connect to the SSID and capture packets for several minutes. Then, click "Stop" in the Wireshark tool to end the packet capture.
After completing the packet capture, the packet file can be analyzed to review the captured information.
Note
There are some other interfaces, such as “eth0” represents Uplink and LAN port interface, and wlan-1-1 is the interface of the first SSID in 2.4GHz radio.
Judy
See how you've made an impact in Zyxel Community this year!
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 146 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 262 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight