Schneider Electric Exchange Community

Discuss and solve problems in energy management and automation. Join conversations and share insights on products and solutions. Co-innovate and collaborate with a global network of peers.

Register Now

By Clicking on "Register Now", you acknowledge that you have read the Privacy Notice for Schneider Electric Exchange.

Knowledge Base
cancel
Showing results for 
Search instead for 
Did you mean: 

Using WireShark to analyse communications on an Ethernet network

Issue

General use of the Wireshark program. 

Product Line

Access Expert, Andover Continuum, EcoStruxure Building Expert, EcoStruxure Building Operation, Pelco, Satchwell MicroNet, Satchwell Sigma, TAC IA Series, TAC INET, TAC Vista

Environment

Ethernet Networks

Cause

General Information on using WireShark.

Resolution

Wireshark is an Ethernet packet analysis programme, Which can be downloaded from:

For the latest version available - Click Here

Or for the stored version please - Click Here

Installing Wireshark.

1 - If necessary, unzip the WireShark executable file to a suitable location on the PC/Laptop you wish the programme to be installed on.

2 - Run the executable file and follow the on-screen instructions.

Rules for capturing LAN traffic using Wireshark:
Do not use a switch or router to connect the LAN capture PC to the network as these will filter important network activity that you will need to see.  You will want to capture everything that is passing over the network at the point of concern.  Usually, this means tapping into the ethernet at the Controller or controllers, that is having an issue.

Here is an example of a device that can be used to easily tap into the network to take the capture.

https://www.amazon.com/midBit-Technologies-LLC-10-100/dp/B00DY77HHK/ref=sr_1_2?ie=UTF8&qid=147066835...

 

The monitoring PC must see all traffic from the controller's point of view. 
 

The monitoring PC can be connected in either two ways.
    a.) Connected to the network at the controller  
    b.) The customers IT department can mirror all the network traffic from the controllers port to another port the PC can be connected to.

If connected to the network at the controllers, the connection must be made through a true ethernet hub.  A hub will not selectively filter important network traffic as a switch or a router will do.

More information on what a "true ethernet hub" is can be found at http://wiki.wireshark.org/HubReference

 

There are however some switches that feature port mirroring, please see How to Configure a NETGEAR Prosafe Plus Switch for Mirroring.

 

If connected to a mirrored port, the port must mirror 100% of the network traffic to and from the controller.  No filtering should be done.  Once a complete capture file has been obtained it can be filtered after the fact using WireShark or EtherReal.

Using Wireshark

1 - Run WireShark.

To start a trace carry out the following:

2 - Choose the "Capture" menu and then select "Interfaces"

Choose the appropriate interface, generally, this can be identified by its IP Address, but if not, then the packets increasing are an indication. Press the "Start" button.

The trace will start and will be similar to the following screenshot.

 

After an appropriate time, the trace can be stopped by selecting "Capture" menu and "Stop"

To save the capture file, choose "File" menu and "Save As".

Tags (2)
No ratings