Got it

Packet capturing and traffic monitoring

Created: Apr 17, 2021 11:38:49Latest reply: Apr 20, 2021 07:43:21 406 5 1 0 0
  HiCoins as reward: 0 (problem unresolved)

Good morning,

I have some questions that need you experts to confirm, please help me.

1. I need to do a traffic capture on an interface, I see the "capture-packet" tool, but I can't see the live capture on the console. What I would like to know is if there is something similar to the Linux command:

tcpdump -i [interface] [filter] -qnvv.

2. I need live traffic monitoring from an interface. At the moment I use the command:

[~ HUAWEI] display interface Eth-Trunk3 | include Last 300

I would like to be able to see it in real-time, similar in juniper to "monitorinterface"

Thank you.

Featured Answers

Recommended answer

chenhui
Admin Created Apr 17, 2021 12:32:05

Posted by chenhui at 2021-04-17 11:39 Hello,Thanks for contacting the Huawei community!We are checking your question and will provide an a ...
Hi,
1. I need to do a traffic capture on an interface, I see the "capture-packet" tool, but I can't see the live capture on the console. What I would like to know is if there is something similar to the Linux command: tcpdump -i [interface] [filter] -qnvv.
======When using the command 'capture-packet' feature, you can assign the destination of the capturing result, for example to the terminal monitor or to a specified file. And there is no command could dump the stored files, you can use the FTP to export that.
2. I need live traffic monitoring from an interface. At the moment I use the command:
[~ HUAWEI] display interface Eth-Trunk3 | include Last 300
I would like to be able to see it in real-time, similar in juniper to "monitorinterface"
======Unfortunately, there is no way to view the real-time result by the device itself, if you need that result strongly, you can use the NMS, such as eSight, to monitor the real-time traffic.
View more
  • x
  • convention:

All Answers
Hello,
Thanks for contacting the Huawei community!
We are checking your question and will provide an answer to you shortly...
View more
  • x
  • convention:

Posted by chenhui at 2021-04-17 11:39 Hello,Thanks for contacting the Huawei community!We are checking your question and will provide an a ...
Hi,
1. I need to do a traffic capture on an interface, I see the "capture-packet" tool, but I can't see the live capture on the console. What I would like to know is if there is something similar to the Linux command: tcpdump -i [interface] [filter] -qnvv.
======When using the command 'capture-packet' feature, you can assign the destination of the capturing result, for example to the terminal monitor or to a specified file. And there is no command could dump the stored files, you can use the FTP to export that.
2. I need live traffic monitoring from an interface. At the moment I use the command:
[~ HUAWEI] display interface Eth-Trunk3 | include Last 300
I would like to be able to see it in real-time, similar in juniper to "monitorinterface"
======Unfortunately, there is no way to view the real-time result by the device itself, if you need that result strongly, you can use the NMS, such as eSight, to monitor the real-time traffic.
View more
  • x
  • convention:

You can use the capture-packet command to capture to your terminal session:


[S1-SP-P0C]capture-packet int X0/0/3 destination terminal

Warning: Mirrored packets will be shown on terminal.

[S1-SP-P0C]

  Packet: 1

  -------------------------------------------------------

  01 00 5e 00 00 05 74 83 ef 4b ae 29 81 00 09 c7

  08 00 45 c0 00 44 31 32 40 00 01 59 5a e7 0a 5a

  02 29 e0 00 00 05 02 01 00 30 01 01 01 01 00 00

  00 00 da 93 00 00 00 00 00 00 00 00 00 00 ff ff

  -------------------------------------------------------


But for me the biggest downside of capture-packet is that it is limited to the first 64 bytes of each packet.



View more
  • x
  • convention:

hemin88
hemin88 Moderator Author Created Apr 19, 2021 08:56:04

Hi there,

You can easily mirror the desired interface to "observed" interface, and capture the new interface easily in the way that fits your tools:

Mirroring


View more
  • x
  • convention:

uzzi
uzzi HCIE Created Apr 20, 2021 07:43:21

2. I need live traffic monitoring from an interface.

Above given answer for "observed" can help however you can change interface traffic parameters from 300 (default) to minimum 10 second by using below command, just in case you only want to see statics part with less time interval.


set flow-stat interval 10


https://support.huawei.com/enterprise/en/doc/EDOC1000097293/8bd4341a/set-flow-stat-interval


Thank you.

Kindest regards,
Uzair
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.