UBNT (WDS) Need help - POSSIBLE TOOL TO HELP

Kick back and hang out in the lounge and talk about almost anything.
User avatar
rkelly1
Experienced Member
 
Posts: 147
Joined: Wed Aug 20, 2014 10:06 pm
Location: Clermont, FL
Has thanked: 12 times
Been thanked: 27 times

Re: Would this tool help you Mola9850

Wed Jun 24, 2015 11:02 am

sirhc wrote:
Example of use:
A WISP sees weird behavior on a port feeding an AP that services 30+ customers so they mirror that port to their computer running WireShark to capture the stream (Yes Wireshark supports this)

The WISP then looks through the garbage looking for something of interest to a specific customer IP so they stop the MIRROR and then add an IP or MAC Filter and restart the MIRROR. Now they am able to determine that the customer is running a bittorrent, or maybe they must have a worm or something of that nature. Or in this case figure out what this strange amount of data is.

Being a WISP for 16 years I can tell you that this feature would be invaluable.

Another thing that would make this feature fast and convent is to mirror the packets to a window on the MIRROR tab negating the need for Wireshark for quick and dirty peaks without all the advanced features Wireshark provides to sort the data.

This is a PRIME EXAMPLE of where this function would be AWESOME.

If people think this feature is a great idea please comment in this thread.


Chris - Take a look at the Packet Sniffer on Mikrotik routers / in RouterOS. I think you are talking about the same functionality for packet sniffing and it IS VERY useful for trouble shooting many situations. You can set a filter for the IP, MAC, protocol, port, direction, etc. You can save it to a local file on the router which overwrites every xxxkb, or stream it to a server running wireshark etc. We exclusively use it locally on the router and don't stream to a server. Simply put in the filter paramters, hit start, and each time you hit the packets button, it updates opens a window with the current set of packets being collected. I think you aren't super familiar with MT so here are some screen shots. They have some terrific tools.

Image

User avatar
rebelwireless
Experienced Member
 
Posts: 607
Joined: Mon Sep 01, 2014 1:46 pm
Has thanked: 31 times
Been thanked: 136 times

Re: UBNT (WDS) Need help - POSSIBLE TOOL TO HELP

Wed Jun 24, 2015 1:23 pm

I use the packet sniffer on 'tik all the time. Handy right on the device but also you can stream it to wireshark. I also have an nTOPng box setup with nprobe listening so I can point the packet sniffer that way and analyze the traffic that way.

It's very handy to take the offending MAC, stream the sniffed traffic to nTOPng, and see what the heck is causing the grief.

User avatar
rkelly1
Experienced Member
 
Posts: 147
Joined: Wed Aug 20, 2014 10:06 pm
Location: Clermont, FL
Has thanked: 12 times
Been thanked: 27 times

Re: UBNT (WDS) Need help - POSSIBLE TOOL TO HELP

Wed Jun 24, 2015 1:25 pm

I'm gunna try that! Sounds great.

User avatar
rebelwireless
Experienced Member
 
Posts: 607
Joined: Mon Sep 01, 2014 1:46 pm
Has thanked: 31 times
Been thanked: 136 times

Re: UBNT (WDS) Need help - POSSIBLE TOOL TO HELP

Wed Jun 24, 2015 1:48 pm

FYI, nProbe (the netflow collector used by ndping) only lets you collect a limited number of records for free. You can get the 'ntopng pro embedded' and runs on a raspberry pi 2 for ~$70 license and use it as a target and collect as much data as you like. The x86 license is like $210.

User avatar
rebelwireless
Experienced Member
 
Posts: 607
Joined: Mon Sep 01, 2014 1:46 pm
Has thanked: 31 times
Been thanked: 136 times

Re: UBNT (WDS) Need help - POSSIBLE TOOL TO HELP

Wed Jun 24, 2015 2:02 pm

Chris, I'm not familiar with the switch capabilities enough to know this. If you have a couple ports in a LAG group, can you mirror the LAG? or are you stuck with just a single port? Port mirroring I think limits you to single port configurations, or maybe mirroring each LAG member to a separate mirror port.

Using nTOPng, you can bridge two ethernet interfaces (say two that were mirrored from the LAG group) and monitor the bridge. Then you don't need nProbe and can do it for free.

User avatar
sirhc
Employee
Employee
 
Posts: 7347
Joined: Tue Apr 08, 2014 3:48 pm
Location: Lancaster, PA
Has thanked: 1597 times
Been thanked: 1318 times

Re: UBNT (WDS) Need help - POSSIBLE TOOL TO HELP

Wed Jun 24, 2015 5:49 pm

OK I am putting up a new v1.3.0rc9 as rc8 would cause the switch to lockup when mirroring to an IP.

Also v1.3.0rc8 would falsely disable POE ports on a reboot.

In a few minutes I will post about using Mirror to an IP and WireShark but do NOT attempt it with any version less than v1.3.0rc9
Support is handled on the Forums not in Emails and PMs.
Before you ask a question use the Search function to see it has been answered before.
To do an Advanced Search click the magnifying glass in the Search Box.
To upload pictures click the Upload attachment link below the BLUE SUBMIT BUTTON.

User avatar
sirhc
Employee
Employee
 
Posts: 7347
Joined: Tue Apr 08, 2014 3:48 pm
Location: Lancaster, PA
Has thanked: 1597 times
Been thanked: 1318 times

Re: UBNT (WDS) Need help - POSSIBLE TOOL TO HELP

Wed Jun 24, 2015 5:58 pm

rebelwireless wrote:Chris, I'm not familiar with the switch capabilities enough to know this. If you have a couple ports in a LAG group, can you mirror the LAG? or are you stuck with just a single port? Port mirroring I think limits you to single port configurations, or maybe mirroring each LAG member to a separate mirror port.

Using nTOPng, you can bridge two ethernet interfaces (say two that were mirrored from the LAG group) and monitor the bridge. Then you don't need nProbe and can do it for free.


OK, you can mirror ports in a LAG but a LAG is only a cluster of ports so if you have a LAG and you want to insure you get all streams you need to select all the ports in a LAG group and then MIRROR them to a single port and capture with WireShark or MIRROR them to an IP and capture it with WireShark.

If mirroring to an IP and you only want WireShark to display only packets MIRRORED from the switch you just need to have a Display Filter "tzsp" (It is case sensitive so must me lowercase).

DO NO TRYING USING MIRROR TO IP UNLESS YOU ARE USING v1.3.0rc9 OR NEWER
previous versions "will" lock up your switch.

CLICK IMAGE BELOW TO VIEW FULL SIZE

MIRROR.jpg
MIRROR.jpg (397.17 KiB) Viewed 22215 times
Support is handled on the Forums not in Emails and PMs.
Before you ask a question use the Search function to see it has been answered before.
To do an Advanced Search click the magnifying glass in the Search Box.
To upload pictures click the Upload attachment link below the BLUE SUBMIT BUTTON.

User avatar
rebelwireless
Experienced Member
 
Posts: 607
Joined: Mon Sep 01, 2014 1:46 pm
Has thanked: 31 times
Been thanked: 136 times

Re: UBNT (WDS) Need help - POSSIBLE TOOL TO HELP

Sun Jun 28, 2015 3:51 pm

chris, are you using sflow or something else to do IP based mirroring?

User avatar
sirhc
Employee
Employee
 
Posts: 7347
Joined: Tue Apr 08, 2014 3:48 pm
Location: Lancaster, PA
Has thanked: 1597 times
Been thanked: 1318 times

Re: UBNT (WDS) Need help - POSSIBLE TOOL TO HELP

Sun Jun 28, 2015 3:59 pm

TZSP

https://en.wikipedia.org/wiki/TZSP

However this is still in BETA and it will only mirror 6 Mbps.

So if you MIRROR a remote port to you laptop running wireshark you will only get 6+/- Mbps of the actual traffic, I wm working with Eric to increase this limitation but we want to crawl before we run.
Support is handled on the Forums not in Emails and PMs.
Before you ask a question use the Search function to see it has been answered before.
To do an Advanced Search click the magnifying glass in the Search Box.
To upload pictures click the Upload attachment link below the BLUE SUBMIT BUTTON.

User avatar
rebelwireless
Experienced Member
 
Posts: 607
Joined: Mon Sep 01, 2014 1:46 pm
Has thanked: 31 times
Been thanked: 136 times

Re: UBNT (WDS) Need help - POSSIBLE TOOL TO HELP

Sun Jun 28, 2015 4:23 pm

sure. do you have the option of just sending headers? often enough, the payload is useless to diagnosing issues, 6Mbps is a LOT of headers.

PreviousNext
Return to The Lounge

Who is online

Users browsing this forum: No registered users and 29 guests