1、抓取控制平面数据包
Internet-R4331-1#monitor capture A control-plane both match mac any any limit packets 10 ##限制抓包数10个,抓满10个后自动停止抓包
Internet-R4331-1#monitor capture A start ##如果没抓满10个,可以手动使用stop停止抓包
Started capture point : A
Internet-R4331-1#show monitor capture A buffer brief
----------------------------------------------------------------------------
# size timestamp source destination dscp protocol
----------------------------------------------------------------------------
0 54 0.000000 10.16.64.67 -> 210.22.10.233 0 BE TCP
1 71 0.001007 10.16.64.67 -> 210.22.10.233 0 BE TCP
2 54 0.001007 10.16.64.67 -> 210.22.10.233 0 BE TCP
3 54 0.001007 210.22.10.233 -> 10.16.64.67 0 BE TCP
4 54 0.001999 210.22.10.233 -> 10.16.64.67 0 BE TCP
5 54 0.001999 10.16.64.67 -> 210.22.10.233 0 BE TCP
6 54 0.074001 10.16.15.44 -> 210.22.10.233 0 BE TCP
7 58 0.432976 210.22.10.234 -> 224.0.0.2 48 CS6 UDP
8 60 0.614974 00:1C:7F:80:A4:36 -> FF:FF:FF:FF:FF:FF -- ARP
9 450 0.826013 00:B6:70:DA:7A:A0 -> 01:00:0C:CC:CC:CC -- LLC
2、抓取接口特定数据包
Internet-R4331-1#monitor capture A int g0/0/0 out match ipv4 host 10.1.13.121 any limit packets 10 ##抓取来自10.1.133.121,经过g0/0/0接口出去的10个包
Internet-R4331-1#monitor capture A start
Started capture point : A
Internet-R4331-1#show monitor capture A buffer brief
----------------------------------------------------------------------------
# size timestamp source destination dscp protocol
----------------------------------------------------------------------------
0 88 0.000000 10.1.13.121 -> 10.253.17.125 0 BE TCP
1 66 0.017065 10.1.13.121 -> 10.253.17.125 0 BE TCP
2 88 15.010009 10.1.13.121 -> 10.253.17.125 0 BE TCP
3 88 15.018056 10.1.13.121 -> 10.253.17.125 0 BE TCP
4 66 15.026051 10.1.13.121 -> 10.253.17.125 0 BE TCP
5 66 15.034062 10.1.13.121 -> 10.253.17.125 0 BE TCP
6 88 30.018056 10.1.13.121 -> 10.253.17.125 0 BE TCP
7 88 30.035054 10.1.13.121 -> 10.253.17.125 0 BE TCP
8 66 30.035054 10.1.13.121 -> 10.253.17.125 0 BE TCP
9 66 30.051059 10.1.13.121 -> 10.253.17.125 0 BE TCP
3、查看抓包信息
Internet-R4331-1#show monitor capture A ##查看抓包配置
Status Information for Capture A
Target Type:
Interface: GigabitEthernet0/0/0, Direction: OUT
Status : Inactive
Filter Details:
IPv4
Source IP: host 10.1.13.121
Destination IP: any
Protocol: any
Buffer Details:
Buffer Type: LINEAR (default)
Buffer Size (in MB): 10
Limit Details:
Number of Packets to capture: 10
Packet Capture duration: 0 (no limit)
Packet Size to capture: 0 (no limit)
Maximum number of packets to capture per second: 1000
Packet sampling rate: 0 (no sampling)
Internet-R4331-1#show monitor capture A buffer brief
----------------------------------------------------------------------------
# size timestamp source destination dscp protocol
----------------------------------------------------------------------------
0 88 0.000000 10.1.13.121 -> 10.253.17.125 0 BE TCP
1 66 0.017065 10.1.13.121 -> 10.253.17.125 0 BE TCP
2 88 15.010009 10.1.13.121 -> 10.253.17.125 0 BE TCP
3 88 15.018056 10.1.13.121 -> 10.253.17.125 0 BE TCP
4 66 15.026051 10.1.13.121 -> 10.253.17.125 0 BE TCP
5 66 15.034062 10.1.13.121 -> 10.253.17.125 0 BE TCP
6 88 30.018056 10.1.13.121 -> 10.253.17.125 0 BE TCP
7 88 30.035054 10.1.13.121 -> 10.253.17.125 0 BE TCP
8 66 30.035054 10.1.13.121 -> 10.253.17.125 0 BE TCP
9 66 30.051059 10.1.13.121 -> 10.253.17.125 0 BE TCP
Internet-R4331-1#show monitor capture A buffer detailed ##通过详细信息,可以了解包的源目IP、MAC和端口等信息
----------------------------------------------------------------------------
# size timestamp source destination dscp protocol
----------------------------------------------------------------------------
0 88 0.000000 10.1.13.121 -> 10.253.17.125 0 BE TCP
0000: 001C7C80 A43600C6 70DA7A98 08004500 .....6..p.z...E.
0010: 004CDA6C 400CCE06 1B4D0A01 85790AFD .J.l@.>..M...y..
0020: ACCDCCE6 2CC85635 E8111785 00ED8018 .}../.V5........
0030: 05909144 00000101 080A285F EE00F7C9 ...D......(_....
Internet-R4331-1#show monitor capture A buffer dump ##抓包能获取HTTP返回值等信息
0
0000: 001C7F80 A43600B6 70DA7A98 08004500 .....6..p.z...E.
0010: 003C0000 40003E06 3C2BAC10 03C40AA4 .<..@.>.<+......
0020: 46190050 F6878A9E 1E2F34A4 519AA012 F..P...../4.Q...
0030: 71209BDA 00000204 05500402 080A54DE q .......P....T.
0040: 48A64216 35490103 0307 H.B.5I....
1
0000: 001C7F80 A43600B6 70DA7A98 08004500 .....6..p.z...E.
0010: 003C0000 40003E06 3C2BAC10 03C40AA4 .<..@.>.<+......
0020: 46190050 F688A4F9 847941A6 56C4A012 F..P.....yA.V...
0030: 71200908 00000204 05500402 080A54DE q .......P....T.
0040: 48A64216 35490103 0307 H.B.5I....
2
0000: 001C7F80 A43600B6 70DA7A98 08004500 .....6..p.z...E.
0010: 0034BE15 40003E06 7E1DAC10 03C40AA4 .4..@.>.~.......
0020: 46190050 F6878A9E 1E3034A4 56DE8010 F..P.....04.V...
0030: 00F834EE 00000101 080A54DE 48C34216 ..4.......T.H.B.
0040: 3565 5e
3
0000: 001C7F80 A43600B6 70DA7A98 08004500 .....6..p.z...E.
0010: 0034BE16 40003E06 7E1CAC10 03C40AA4 .4..@.>.~.......
0020: 46190050 F6878A9E 1E3034A4 58F58010 F..P.....04.X...
0030: 010D32C1 00000101 080A54DE 48C44216 ..2.......T.H.B.
0040: 3565 5e
4
0000: 001C7F80 A43600B6 70DA7A98 08004500 .....6..p.z...E.
0010: 0578BE17 40003E06 78D7AC10 03C40AA4 .x..@.>.x.......
0020: 46190050 F6878A9E 1E3034A4 58F58010 F..P.....04.X...
0030: 010D0237 00000101 080A54DE 48CB4216 ...7......T.H.B.
0040: 35654854 54502F31 2E312032 3030204F 5eHTTP/1.1 200 O
0050: 4B0D0A53 65727665 723A206E 67696E78 K..Server: nginx
0060: 2F312E31 322E320D 0A446174 653A2054 /1.12.2..Date: T
0070: 75652C20 3135204A 616E2032 30313920 ue, 15 Jan 2019
0080: 30353A35 303A3038 20474D54 0D0A436F 05:50:08 GMT..Co
0090: 6E74656E 742D5479 70653A20 74657874 ntent-Type: text
00A0: 2F68746D 6C3B6368 61727365 743D7574 /html;charset=ut
00B0: 662D380D 0A547261 6E736665 722D456E f-8..Transfer-En
00C0: 636F6469 6E673A20 6368756E 6B65640D coding: chunked.
00D0: 0A566172 793A2041 63636570 742D456E .Vary: Accept-En
00E0: 636F6469 6E670D0A 436F6E74 656E742D coding..Content-
00F0: 456E636F 64696E67 3A20677A 69700D0A Encoding: gzip..
0100: 0D0A6432 390D0A1F 8B080000 00000000 ..d29...........
0110: 03BD1A6B 6F1BC7F1 73FC2BD6 97227450 ...ko...s.+.."tP
0120: 5147C9B2 1C31A403 5BB25107 B69BC609 QG...1..[.Q.....
0130: 8AC20884 E5DD925C EB7877B9 3BCAA215 .......\.xw.;...
0140: 012D52BB 41122729 521748DB 0F4D8B14 .-R.A.')R.H..M..
0150: 46D13A29 D2D6E923 E97F2942 C9FE179D F.:)...#..)B....
0160: D9D7DD2D 49E9A8B4 1524DD63 67E73DB3 ...-I....$.cg.=.
0170: B37BD3F2 F9F6B913 047E5A69 360A18C9 .{.......~Zi6...
0180: 46316B3B 19DBC95C 2F4D1D39 86E39DC8 F1k;...\/M.9....
0190: 1F2DD228 64F5808E A261468A 0FF52C8A .-.(d....aF...,.
01A0: 3B345910 980E814E B9CF006E D7C021EC ;4Y....N...n..!.
01B0: ED3A0F7D B6D3244B 8D46E324 1FC45192 .:.}..$K.F.$..Q.
01C0: D1307BDE 00ED4906 5DC161CE 512BE0E1 .0{...I.].a.Q+..
01D0: 164958D0 76C448DA 672C736C 09483F61 .IX.v.H.g,sl.H?a
01E0: DDB6D3CF B2B8E9BA A361B8C3 69B4E8B3 .........a..i...
01F0: ED284E17 69C0E1CD A2170D5C 41357041 .(N.i......\A5pA
0200: 70968428 BBDBA129 5B442510 57A94810 p..(...)[D%.W.H.
0210: 3C363E54 9EC467F3 FCFF9309 ECB409F2 <6>T..g.........
0220: A6E90BDB EDE5C6D2 6A633597 EEE4BF7F ........jc5.....
0230: F8E10DDE 2541462E 5F5C7B4D C99C7A09 ....%AF._\{M..z.
0240: 8F339226 DEDC4A94 53537710 F9A0537E .3.&..J.SSw...S~
0250: 3B59BC09 1ED572E5 FBA24EA5 42FA6078 ;Y....r...N.B.`x
0260: 0F3C8B7B 51E828BB 6983F001 EDB1D4D8 .<.{Q.(.i.......
0270: 0F40946F B64EDE60 A1CFBBAF 01F70A25 [email protected].`.......%
0280: 0F63C022 3DB9CF7D 9F0136EE B79D61CA .c."=..}..6...a.
0290: 92CBBE43 B6693004 27D70866 816F7A69 ...C.i0.'..f.ozi
02A0: D2DDCCA2 2D9CAFE6 9C397369 6DFDE2D9 ....-....9sim...
02B0: D5E75696 36CE2C6F 9C3F7B66 E9E285A5 ..V.6.,o.?{f....
02C0: 95F3974E 9F593EB3 7E7E7579 7D797563 ...N.Y>.~~uy}yuc
02D0: 796365AD B176E1C2 85E7D657 1A8DD3AB yce..v.....W....
02E0: AB2B8DE5 D32B1B67 2FAE9D75 B42B1588 .+...+.g/..u.+..
02F0: D6248F35 E4B11627 EC3A4BB6 59F26A12 .$.5...'.:K.Y.j.
0300: D414D5DA D1CE9BB0 9AF15208 69E20534 ..........R.i..4
0310: 4DDB8E72 F7BA885B D06AC6C2 0C2D5088 M..r...[.j...-P.
0320: 7A69DE42 D8DFA4DB 545AA810 FDDB3421 zi.B....TZ....4!
0330: 0AD926E0 E9F21E69 937218F7 697A5D86 ..&....i.r..iz].
0340: 779364C9 90E5C900 835C2688 A6350747 w.d......\&..5.G
0350: BC619200 5BCD1CBF 7C41DA6D 520B582F .a..[...|A.mR.X/
0360: AA911708 E825BAC9 BCAC469A A4768B05 .....%....F..v..
0370: 10B1AC66 1204A291 4942DCE5 99A3C836 ...f....IB.....6
0380: E834E551 087C3BE0 F9CF2D35 4E379CE9 .4.Q.|;...-5N7..
0390: 908A2384 9C0111B2 5BDF6114 BC1A617E ..#.....[.a...a~
03A0: 6001F991 07C6C391 23ED06A0 D6E4D9B4 `.......#.......
03B0: D17BA7B0 F44A146F D08CC248 D91C29A3 .{...J.o...H..).
03C0: B728E4B2 5761DA85 E1F7862C 1935419E .(..Wa.....,.5A.
03D0: B25534D0 F9203812 66BD4FC3 1EBB303C .U4.. 8.f.O...0<
03E0: 1FF34944 8A6D24F6 12E45B0E D9DCA625 ..ID.m$...[....%
03F0: 13AC746E 183D5237 12DE6298 FA031E56 ..tn.=R7..b....V
0400: C731DA11 131CE329 7B658B4B 1A55ADA5 .1.....){e.K.U..
0410: 382AA3E8 D180EE8C 244B5511 C93996E5 8*......$KU..9..
0420: 63BE1D65 F3E11153 2C343EEB 429CCC87 c..e...S,4>.B...
0430: 47CEB110 D12C529A AE2A16CE 70C55ABE G....,R..*..p.Z.
0440: D8CF0613 E868BA35 8D2DB12C 4E598F65 .....h.5.-.,NY.e
0450: C0DB5860 0DBD22EA 8F8D6840 B98866E5 ..X`.."[email protected].
0460: 4990F058 964EAEEC 3686C1DC 62C10C1B I..X.N..6...b...
0470: 090BB7A7 C932BBBC A030C342 32E41245 .....2...0.B2..E
0480: A54C4187 BC4E598F A7CE424A 73F35649 .LA..NY...BJs.VI
0490: 3200EF2C 94BDABCA 528EEEE8 2CA80832 2..,....R...,..2
04A0: C25698A9 83AE1C27 C585AD92 C430C159 .V.....'.....0.Y
04B0: 2061C753 6A525E08 EF38AC63 BD846690 a.SjR^..8.c..f.
04C0: CD0D5F22 332E0C22 6F8B25A5 9747E619 .._"3.."o.%..G..
04D0: 3907D016 275710D3 CCF321FD 766838D5 9...'W....!.vh8.
04E0: B9673B84 9E653985 51130864 EE41F4B2 .g;..e9.Q..d.A..
04F0: 328BAC02 60F17102 561332CE 567E3101 2...`.q.V.2.V~1.
0500: 4F7D58C8 450952C9 4C086EC9 40D3FE70 O}[email protected]
0510: 1E0C006E 61C07DC2 55160E81 83DAAE23 ...na.}.U......#
0520: 62A7E940 142E3850 07780C6A 7278EC76 [email protected]
0530: C533C37B 1C42B9EA 5E04D584 9799718A .3.{.B..^.....q.
0540: C1AB0030 100AB068 33F32CB2 A67E4201 ...0...h3.,..~B.
0550: F43D5620 FA1E82D0 DCA2D80A 994CC3FA .=V .........L..
0560: 01772F81 1E52991E C604B7CA 671428E6 .w/..R......g.(.
0570: 4B09B857 2BDB5797 5A206D97 074CBA7E K..W+.W.Z m..L.~
0580: 853250D0 76E5 .2P.v.
4、查看抓包配置参数
JA-R4331#show monitor capture A parameter
monitor capture A interface GigabitEthernet0/0/1 IN
monitor capture A match ipv4 any host 10.11.3.11
monitor capture A buffer size 10
monitor capture A limit packets 1000 pps 1000
5、导出路由器进行分析
JA-R4331#monitor capture A export tftp://10.1.20.16/1.cap
!
Exported Successfully
6、对抓包功能debug
R1#debug epc provision
R1#debug epc capture-point
7、进阶操作
R01#monitor capture A match ipv4 protocol tcp any any control-plane both limit packets 20 buffer size 5 circular interface GigabitEthernet 0/0/1
解释:配置EPC的名字为A,匹配ipv4的TCP协议,针对接口G0/0/1,源是any,目的也是any,抓取的是控制层面进出的报文,报文数量为20个,存储报文的的空间大小为5MB,采取当buffer满了时,丢掉旧报文的方式。
8、参考资料
Cisco IOS/IOS-XE 嵌入式抓包(Embedded Packet Capture)使用指南