Got it

Procedure to Capture packets on a router and SFTP to U2000

Latest reply: Feb 16, 2022 10:13:10 888 40 16 0 0

Problem description

This gives the procedure to capture packets and sftp it to U2000. This procedure is helpful in  situations such as:

-       When an attack is observed on a port on a router and packets needs to be captured for further analysis.

-       Packets drops are experienced for a service and further deep dive needed to understand how those packets are              handled when they enter or leave the router ports.

-       Deep dive to understand why a newly configured service is not going through.

-       Investigate if there is a Layer 2 or a Layer 3 loop after analysis a packet capture.

     Below, we will focus our attention on the capturing of packets when an attack happens on a router port which we will               term “Procedure of blackhole

     Below is an example of graph showing an unusual traffic received on the port of a router which gives suspicion of an                 attack.

          Graph showing an attack on a port of the Router


Handling Process for Procedures of blackhole

 

When you see the continuous attacking traffic chocking on one port, for example inbound traffic on the port GiX/Y/Z of a router, you need to capture the packet of the inbound traffic (you need to capture the outbound if the attacking traffic is on the outbound direction of the port) and then sftp it to U2000. Below is a step-by-step process on how to go about it:

 

STEP 1 : Capture the packets using the command below and save on using a file name with extension *.pcap:

#

capture-packet forwarding interface GigabitEthernet x/y/z inbound time-out 36000 packet-num 1000 packet-len 64 file filename.pcap    

#

STEP 2 : Check the packet capture status by issuing the command below

#

display capture-packet information

#

This will help confirm if you already capturing packets or not.

      display capture


       STEP 3 : In step 2 above, when you see the “instance saved packet number” is 1000, use below command to release the             capturing task

#

undo capture-packet forwarding interface GigabitEthernet x/y/z inbound

#

capture-packet free all

#

The above 3 steps were to capture the packet. The following steps below are to SFTP the captured packets to the U2000.          

                                                                                                                                                                                            

STEP 4 : Define the path of the captured packets on the router by using the command below :

#

cd cfcard2:/capture

#

View the directory to confirm captured file is present.

#

Dir cfcard2/:

#

STEP 5 : SFTP the captured packets to the U2000 Server.

#

System-view

sftp U2000_Server_IP

#   

Username is “root”, password is “*************”

binary

#

put filename.zip

#

       ftp transfer


         STEP 6 : Download captured packets to PC and confirm the attacking packet and ip with WiresharkCreate the session of               U2000. Username is “root”, password is “***********”

       download file 1

 

       download to pc2


        Open the U2000 session and choose your local disk C, right click the captured file and download to your local disk C.


       download file3


         You now successfully have the *.pcap file on your PC which you can use any packet analyzer such as wireshark to analyze             the packets.

 

 

 


The post is synchronized to: Author group

Lucfabrice
MVE Author Created Nov 24, 2021 18:02:15

  • x
  • convention:

shakeela
shakeela Created Nov 24, 2021 18:22:52 (1) (0)
 
SaraZahid
SaraZahid Created Nov 24, 2021 18:23:14 (1) (0)
 
zaheernew
zaheernew Created Nov 24, 2021 18:30:53 (1) (0)
Great  
lucian2003
lucian2003 Created Nov 25, 2021 03:43:39 (1) (0)
 
taha_29four
taha_29four Created Nov 25, 2021 06:14:33 (1) (0)
well done my friend  
Laiheang
Laiheang Created Dec 19, 2021 08:05:33 (0) (0)
oh  
Saqibaz
Saqibaz Created Feb 15, 2022 15:46:02 (1) (0)
 
Saqibaz
Saqibaz Created Feb 16, 2022 05:25:23 (1) (0)
 
great sharing
View more
  • x
  • convention:

Vlada85
MVE Author Created Nov 24, 2021 18:13:57

Thank you
View more
  • x
  • convention:

Good
View more
  • x
  • convention:

SaraZahid
SaraZahid Created Nov 24, 2021 18:23:31 (1) (0)
 
Thanks for sharing
View more
  • x
  • convention:

Serges_armel
Serges_armel Created Nov 28, 2021 20:44:18 (0) (0)
Yes  
Thanks for sharing
View more
  • x
  • convention:

very usefull for packet analysis, thanks for sharing
View more
  • x
  • convention:

Beneficial content
View more
  • x
  • convention:

Lucfabrice
Lucfabrice Created Nov 26, 2021 14:56:49 (0) (0)
Thanks Wissal  
Very useful. Thanks.
View more
  • x
  • convention:

123
Back to list

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.