Solved

Help on capturing voice packets

Posted on 2014-10-22
7
300 Views
Last Modified: 2014-11-19
My netgear switch connects to a SonicWALL router which connects to the internet. I have created subinterfaces on the SonicWALL X0 Interface to connect that to a NetGear switch.

I have setup two VLANs in my Netgear switch.

VLAN 10 - Data - 10.10.10.x/24
VLAN 50 - Voice - 172.16.10.x/24

All ports are untagged for data and tagged for Voice vlan. and the devices are all working fine.

I face some issue with the phones and want to capture voice packets to see whats going on. I have connected a PC on port 0/2 and want to capture voice and data packets on port 0/3 on the netgear switch. Due to VLAN implementation, I only see the packets on my own port.

I followed the NetGear documentation and mirrored port 0/3 to destination port 0/2 where my monitor PC is connected, still I don't see any packets.

Please advise where to place the monitor host or any other suggestion to capture the Voice VLAN packets.

My switch and router model is below.

M4100-50G ProSafe 48-port Gigabit L2+ Intelligent Edge Managed Switch
Firmware Version 10.0.1.28

SonicWALL NSA 2400
Firmware 5.9

Thank you.

Network Diagram
0
Comment
Question by:Miftaul
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 
LVL 14

Assisted Solution

by:Otto_N
Otto_N earned 400 total points
ID: 40396968
I assume that you configured the monitor session using the following commands on the Netgear:
  monitor session 1 mode
 monitor session 1 source interface 0/3
 monitor session 1 destination interface 0/2

Open in new window


You can verify that this is running by doing the "show monitor session 1" command.

The only other requirement is that your monitor PC's NIC must be in promiscuous mode (a tick box in the Wireshark Capture Options), and that you specify the correct NIC on Wireshark.

Hope this helps...
0
 
LVL 11

Author Comment

by:Miftaul
ID: 40397015
I set the NetGEAR from GUI, Let me try CLI and get back to you
0
 
LVL 14

Assisted Solution

by:Otto_N
Otto_N earned 400 total points
ID: 40397027
Should be the same, but I prefer CLI (less point and click and wait...)

You can just do the "show monitor session 1" on CLI and post that.  It would show you a monitor session created in GUI as well.
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 11

Author Comment

by:Miftaul
ID: 40397238
I am testing teh source port 0/27 and destination port 0/45. The moment i enter "monitor session 1 mode" I loose my remote access to the PC.
(M4100-50G) #show monitor session 1

Session ID   Admin Mode   Probe Port   Mirrored Port           Type
----------   ----------   ----------   ---------------------   -----
1            Enable       0/45         0/27                    Rx,Tx

Open in new window

Any Advise
0
 
LVL 14

Accepted Solution

by:
Otto_N earned 400 total points
ID: 40398649
In theory, the host connected to the destination port should still be able to communicate normally on that port - or at least, that's how it is on Cisco devices, I'm still trying to confirm this for the Netgear equipment.  However, depending on the traffic of the source port, you may actually exceed the destination port capacity - You could verify this through the "show interface ethernet 0/45" command, and checking for continuous increase in Receive/Transmit Packets Discarded-counters.

One way around this is to have two connections to your monitor PC - one for normal LAN & remote connectivity, the other for the Wireshark capture.  Or you can try to minimise the traffic on the source port (closing applications, or doing the troubleshooting after-hours).  Also check that your probe port is working at 1000Mbps/Full duplex to maximise bandwidth.
0
 
LVL 5

Assisted Solution

by:Paul Wagner
Paul Wagner earned 100 total points
ID: 40417184
Do you have a VoIP phone system on site? Can you capture packets from it?
Can you capture packets from the sonicwall?

Are you able to change a switch port with the PC to the voice VLAN and then do port mirroring? I have done mirroring before on HP enterprise switches and am pretty sure the ports need to be in the same VLAN in order for it to work.
0
 
LVL 11

Author Closing Comment

by:Miftaul
ID: 40452406
I had to connect two separate cable, one for port monitoring using Wireshark and other for regular LAN traffic.

Thank you so much Otto_N.

Thank you pterodactylptimeptravel for your insights.
0

Featured Post

How Do You Stack Up Against Your Peers?

With today’s modern enterprise so dependent on digital infrastructures, the impact of major incidents has increased dramatically. Grab the report now to gain insight into how your organization ranks against your peers and learn best-in-class strategies to resolve incidents.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microservice architecture adoption brings many advantages, but can add intricacy. Selecting the right orchestration tool is most important for business specific needs.
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …

729 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question