VoIP Ethernet Capture TMG800

From TBwiki
Revision as of 12:57, 24 February 2015 by Cbilodeau (Talk | contribs)
Jump to: navigation, search

Applies to version(s): v2.7

Capturing using the TMG800's internal host

The TMG800's internal host can be used for capturing packets that are mirrored from the VOIP0 and/or VOIP1 physical ports.

Start Capture

You need two SSH sessions to capture the traffic:

First, access the Tmedia management interface using SSH. Then, access the telecom baseboard using telnet 172.31.1.1 ( prompt is tml> )
To capture VoIP0 traffic:

mv88eMonitor 0x1 0x1 2 600

To capture VoIP1 traffic:

mv88eMonitor 0x2 0x2 2 600

In the example the duration is 600 seconds, thus will capture traffic for 10 minutes

Second, access the Tmedia management interface using SSH ( prompt is [root@TBxxxxxx ~]# )

tcpdump -i mgmt0 -s 1500 -w capture_file.cap

You will see something like this:

tcpdump: listening on mgmt0, link-type EN10MB (Ethernet), capture size 1500 bytes


Stop Capture

When you're ready, stop the capture by pressing control-C on the shell that was running tcpdump command
You will see something like this:

364 packets captured
590 packets received by filter
0 packets dropped by kernel


Download Capture

To download the capture, use SSH secure copy ("sftp") to the Tmedia management port. This can be done on Windows using tools like Filezilla or WinSCP.
The file will be located in

/root

References

Personal tools