How to configure wireshark to receive packet capture from Instant AP?

Aruba Employee
Aruba Employee

Introduction :

 

Wireless packet capture is basically enabled on a BSSID of an Instant AP and the captured frames are pushed to a wired PC running packet capture utility such as, Wireshark.  It is general practice to use Aruba UDP port 5555 to destined the captured traffic.
 

Feature Notes :

 

  • New versions of Wireshark do not come with ARUBA_ERM port pre-configured
  • One can download the Aruba version of Wireshark from Aruba Support site
  • The wired station running packet capture application need not necessary to be in same subnet. It can be across subnets as along a IAP has good IP connectivity.

 

EnvironmentThis article applies to Aruba Instant Access Points and Aruba Mobility Controllers.

 

Network Topology : Aruba IAP   ----->  Wired Station running packet capture application.

 

Configuration Steps :

 

Configure the Wireshark as below to see the captured frames:

 
  1. Download the latest version of Wireshark. If you already have installed, update it to the latest.
  2. Open Wireshark and then go to  Edit ---> Preferences



    User-added image

    3.   Expand "Protocols" and find "ARUBA_ERM"   [ERM stands for Encapsulated Remote Mirroring]



    User-added image



    4. Mentioned the value for "ARUBA_ARM UDP Port numbers"  as 5555.

    (NOTE:  This value should be same as the port number mentioned in the "pcap start" command on IAP)


    5. Now start the capture and use the filter as "wlan"



    User-added image
Version history
Revision #:
1 of 2
Last update:
‎07-03-2014 07:55 PM
Updated by:
 
Labels (1)
Contributors
Comments
Juansh28

Hello 

Someone has experience using:

this how to

https://community.arubanetworks.com/aruba/attachments/aruba/tkb@tkb/270/1/Packet%20Capture%20with%20Aruba%20Controller.pdf

Under 

Pc local firewall down

windows 8.1

wireshark 2.6.1

Name:Aruba Operating System Software.
Model:Aruba7010
Version:6.5.4.5
Compiled:2018-02-10 at 11:51:07 UTC (build 63641) by p4build

Capture-controller.JPGCapture-wireshark.JPGCapture-statisctic-protocol.JPG

 

I am not receiving 802.11 traffic only multicast ipv6. Any idea about this issue, 

Search Airheads
cancel
Showing results for 
Search instead for 
Did you mean: