Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

clearpass - collecting packet capture corrupt

This thread has been viewed 11 times
  • 1.  clearpass - collecting packet capture corrupt

    MVP
    Posted Jun 18, 2014 04:55 AM

    I'm trying to retrieve a packet capture from clearpass.

    The way I thought this could be done is via Administration » Server Manager » Server Configuration » Collect Logs

    Here I select only " Capture network packets Duration of dump: 60 secs.".

     

    After triggering the authentication I want to see, I stop the doanload (also tried letting it run for full duration) and then download the resulting .tar.gz file.

    Winrar however says this tar.gz file is corrupt and won't let me open it. 7Zip does manage to open te file and gives me a .tar file. 

    This .tar I can open with both winrar and 7Zip. The final file is a file without extention which cannot be loaded into wireshark.

     

    How do I get a readable packet capture so I can analyze whats going wrong with avaya ers4500 mac auth?



  • 2.  RE: clearpass - collecting packet capture corrupt
    Best Answer

    MVP
    Posted Jun 18, 2014 04:57 AM

    Right.. first check help, then continue.

    That file inside the .tar which in turn was inside a tar.gz appeared to be a .zip file with no extention.

    Change extention to .zip and I can extract the .cap file I wanted.

     

    Might be a good idea to actualy give the zip archiove an actual .zip extention? 



  • 3.  RE: clearpass - collecting packet capture corrupt

    EMPLOYEE
    Posted Jun 18, 2014 08:51 AM
    Thanks @koenv for the information.

    I've noticed in the latest releases of chrome the zip file extension is being changed. If you need to do a backup or packet capture I would recommend you use Firefox or Safari until engineering can investigate it more.