This command continuously captures both incoming and outgoing packets of a monitoring port that match the specified criteria in a circular fashion until stopped. If you have configured the Sensor to receive and send traffic on a single port, you can use this command to capture packets.
The packets are captured by the circular buffer. The circular buffer size varies based on the NS-series or Virtual IPS Sensor. For example, the buffer size for NS9100 is 100MB, the buffer size for VM600 is 58 MB, etc. On reaching the end of the buffer, the oldest or starting packets in buffer are overwritten till the circular packet capture is stopped forcefully. The captured packets are saved in the /tftpboot/capture.pcap file on the Sensor. The saved file is sent to the Manager.
Note
If you have configured the Manager to send captured packets to a SPAN port, you cannot capture packets by using this command.
Syntax:
pktcapture-circular intfport <monitoring_port> <filter>
Parameter | Description |
|---|---|
monitoring_port | Port for capturing incoming and outgoing packets.
|
filter | BPF (Berkeley Packet Filter) for capturing packets. If no filter is provided, all packets are captured.
|
Sample Output:
intruShell@NS7350-101> pktcapture-circular intfport g1/1 ""
A packet capture file will be sent to the Manager, as per the configuration.
Do you want to proceed with the packet capture session?
Please enter Y to confirm: Y
pktcapture: capture all...
Applicable to:
NS9600 (standalone), NS9500 (standalone), NS9x00, NS7600, NS7500, NS7x50, NS7x00, NS5x00, NS3600, NS3500, NS3x00 series, and Virtual IPS Sensors.