Capturing methodologies

In order to capture the right set of a packets stream, you would need to know where to place your protocol analyser. Depending on the requirements (source of packets, number of packets, type of packets, and more), a protocol analyzer needs to be placed at a certain point in the network. Also, a few configuration changes in a network device may be necessary, such as switch configuration changes (mirroring is done in network switches to capture packets from one or more sources). The following sub sections discuss a few means of assessing the best way of configuring protocol analyses in certain types of topology.

Get Wireshark 2 Quick Start Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.