Solved

Help on capturing voice packets

Posted on 2014-10-22
7
296 Views
Last Modified: 2014-11-19
My netgear switch connects to a SonicWALL router which connects to the internet. I have created subinterfaces on the SonicWALL X0 Interface to connect that to a NetGear switch.

I have setup two VLANs in my Netgear switch.

VLAN 10 - Data - 10.10.10.x/24
VLAN 50 - Voice - 172.16.10.x/24

All ports are untagged for data and tagged for Voice vlan. and the devices are all working fine.

I face some issue with the phones and want to capture voice packets to see whats going on. I have connected a PC on port 0/2 and want to capture voice and data packets on port 0/3 on the netgear switch. Due to VLAN implementation, I only see the packets on my own port.

I followed the NetGear documentation and mirrored port 0/3 to destination port 0/2 where my monitor PC is connected, still I don't see any packets.

Please advise where to place the monitor host or any other suggestion to capture the Voice VLAN packets.

My switch and router model is below.

M4100-50G ProSafe 48-port Gigabit L2+ Intelligent Edge Managed Switch
Firmware Version 10.0.1.28

SonicWALL NSA 2400
Firmware 5.9

Thank you.

Network Diagram
0
Comment
Question by:Miftaul
  • 3
  • 3
7 Comments
 
LVL 14

Assisted Solution

by:Otto_N
Otto_N earned 400 total points
ID: 40396968
I assume that you configured the monitor session using the following commands on the Netgear:
  monitor session 1 mode
 monitor session 1 source interface 0/3
 monitor session 1 destination interface 0/2

Open in new window


You can verify that this is running by doing the "show monitor session 1" command.

The only other requirement is that your monitor PC's NIC must be in promiscuous mode (a tick box in the Wireshark Capture Options), and that you specify the correct NIC on Wireshark.

Hope this helps...
0
 
LVL 11

Author Comment

by:Miftaul
ID: 40397015
I set the NetGEAR from GUI, Let me try CLI and get back to you
0
 
LVL 14

Assisted Solution

by:Otto_N
Otto_N earned 400 total points
ID: 40397027
Should be the same, but I prefer CLI (less point and click and wait...)

You can just do the "show monitor session 1" on CLI and post that.  It would show you a monitor session created in GUI as well.
0
Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

 
LVL 11

Author Comment

by:Miftaul
ID: 40397238
I am testing teh source port 0/27 and destination port 0/45. The moment i enter "monitor session 1 mode" I loose my remote access to the PC.
(M4100-50G) #show monitor session 1

Session ID   Admin Mode   Probe Port   Mirrored Port           Type
----------   ----------   ----------   ---------------------   -----
1            Enable       0/45         0/27                    Rx,Tx

Open in new window

Any Advise
0
 
LVL 14

Accepted Solution

by:
Otto_N earned 400 total points
ID: 40398649
In theory, the host connected to the destination port should still be able to communicate normally on that port - or at least, that's how it is on Cisco devices, I'm still trying to confirm this for the Netgear equipment.  However, depending on the traffic of the source port, you may actually exceed the destination port capacity - You could verify this through the "show interface ethernet 0/45" command, and checking for continuous increase in Receive/Transmit Packets Discarded-counters.

One way around this is to have two connections to your monitor PC - one for normal LAN & remote connectivity, the other for the Wireshark capture.  Or you can try to minimise the traffic on the source port (closing applications, or doing the troubleshooting after-hours).  Also check that your probe port is working at 1000Mbps/Full duplex to maximise bandwidth.
0
 
LVL 5

Assisted Solution

by:Paul Wagner
Paul Wagner earned 100 total points
ID: 40417184
Do you have a VoIP phone system on site? Can you capture packets from it?
Can you capture packets from the sonicwall?

Are you able to change a switch port with the PC to the voice VLAN and then do port mirroring? I have done mirroring before on HP enterprise switches and am pretty sure the ports need to be in the same VLAN in order for it to work.
0
 
LVL 11

Author Closing Comment

by:Miftaul
ID: 40452406
I had to connect two separate cable, one for port monitoring using Wireshark and other for regular LAN traffic.

Thank you so much Otto_N.

Thank you pterodactylptimeptravel for your insights.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Hello to you all, I hear of many people congratulate AWS (Amazon Web Services) on how easy it is to spin up and create new EC2 (Elastic Compute Cloud) instances, but then fail and struggle to connect to them using simple tools such as SSH (Secure…
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question