How to Capture Switch Packets via Port Mirroring?

Options
Zyxel_Tina
Zyxel_Tina Posts: 786 image  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments
edited April 9 in Port & VLAN settings

Why capture packet?

In troubleshooting scenarios, packet captures are often essential. For example, you may need to verify if the switch is correctly obtaining an IP from an upstream device like a gateway, router, or DHCP server. This guide provides step-by-step instructions on how to accomplish this.

Typology

image.png

Steps:

In the Switch GUI

  • Choose the Mirroring feature
  • Choose the monitor port (connected to your PC), and mirrored port (connected to the uplink device)
  • Click Apply

Note: The steps for setting up mirroring can vary between different switches.

image.png

In the laptop where Wireshark has already installed inside

  • Click the “Capture” button on the dashboard, or the gear icon on the menu bar.
image.png
  • Select the Ethernet interface
image.png
  • Capture packets for several minutes. Then, click "Stop" in the Wireshark tool to end the packet capture.

After completing the packet capture, the packet file can be analyzed to review the captured information.

Zyxel Tina