Solved

Help on capturing voice packets

Posted on 2014-10-22
7
298 Views
Last Modified: 2014-11-19
My netgear switch connects to a SonicWALL router which connects to the internet. I have created subinterfaces on the SonicWALL X0 Interface to connect that to a NetGear switch.

I have setup two VLANs in my Netgear switch.

VLAN 10 - Data - 10.10.10.x/24
VLAN 50 - Voice - 172.16.10.x/24

All ports are untagged for data and tagged for Voice vlan. and the devices are all working fine.

I face some issue with the phones and want to capture voice packets to see whats going on. I have connected a PC on port 0/2 and want to capture voice and data packets on port 0/3 on the netgear switch. Due to VLAN implementation, I only see the packets on my own port.

I followed the NetGear documentation and mirrored port 0/3 to destination port 0/2 where my monitor PC is connected, still I don't see any packets.

Please advise where to place the monitor host or any other suggestion to capture the Voice VLAN packets.

My switch and router model is below.

M4100-50G ProSafe 48-port Gigabit L2+ Intelligent Edge Managed Switch
Firmware Version 10.0.1.28

SonicWALL NSA 2400
Firmware 5.9

Thank you.

Network Diagram
0
Comment
Question by:Miftaul
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 
LVL 14

Assisted Solution

by:Otto_N
Otto_N earned 400 total points
ID: 40396968
I assume that you configured the monitor session using the following commands on the Netgear:
  monitor session 1 mode
 monitor session 1 source interface 0/3
 monitor session 1 destination interface 0/2

Open in new window


You can verify that this is running by doing the "show monitor session 1" command.

The only other requirement is that your monitor PC's NIC must be in promiscuous mode (a tick box in the Wireshark Capture Options), and that you specify the correct NIC on Wireshark.

Hope this helps...
0
 
LVL 11

Author Comment

by:Miftaul
ID: 40397015
I set the NetGEAR from GUI, Let me try CLI and get back to you
0
 
LVL 14

Assisted Solution

by:Otto_N
Otto_N earned 400 total points
ID: 40397027
Should be the same, but I prefer CLI (less point and click and wait...)

You can just do the "show monitor session 1" on CLI and post that.  It would show you a monitor session created in GUI as well.
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 11

Author Comment

by:Miftaul
ID: 40397238
I am testing teh source port 0/27 and destination port 0/45. The moment i enter "monitor session 1 mode" I loose my remote access to the PC.
(M4100-50G) #show monitor session 1

Session ID   Admin Mode   Probe Port   Mirrored Port           Type
----------   ----------   ----------   ---------------------   -----
1            Enable       0/45         0/27                    Rx,Tx

Open in new window

Any Advise
0
 
LVL 14

Accepted Solution

by:
Otto_N earned 400 total points
ID: 40398649
In theory, the host connected to the destination port should still be able to communicate normally on that port - or at least, that's how it is on Cisco devices, I'm still trying to confirm this for the Netgear equipment.  However, depending on the traffic of the source port, you may actually exceed the destination port capacity - You could verify this through the "show interface ethernet 0/45" command, and checking for continuous increase in Receive/Transmit Packets Discarded-counters.

One way around this is to have two connections to your monitor PC - one for normal LAN & remote connectivity, the other for the Wireshark capture.  Or you can try to minimise the traffic on the source port (closing applications, or doing the troubleshooting after-hours).  Also check that your probe port is working at 1000Mbps/Full duplex to maximise bandwidth.
0
 
LVL 5

Assisted Solution

by:Paul Wagner
Paul Wagner earned 100 total points
ID: 40417184
Do you have a VoIP phone system on site? Can you capture packets from it?
Can you capture packets from the sonicwall?

Are you able to change a switch port with the PC to the voice VLAN and then do port mirroring? I have done mirroring before on HP enterprise switches and am pretty sure the ports need to be in the same VLAN in order for it to work.
0
 
LVL 11

Author Closing Comment

by:Miftaul
ID: 40452406
I had to connect two separate cable, one for port monitoring using Wireshark and other for regular LAN traffic.

Thank you so much Otto_N.

Thank you pterodactylptimeptravel for your insights.
0

Featured Post

DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
SD - WAN 2 65
traffic flow without STP 9 56
Fiber optic multimode cable issue 6 67
Cisco Edge Routers for BGP 6 97
This article is focussed on erradicating the confusion with slash notations. This article will help you identify and understand the purpose and use of slash notations. A deep understanding of this will help you identify networks quicker especially w…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question