Community discussions

MikroTik App
 
User avatar
rfc1149
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 77
Joined: Fri May 15, 2020 4:26 am
Location: England

Packet streaming from ROS and remote capture with Wireshark

Mon Jan 24, 2022 4:50 pm

Hello everyone, I see that this solution was never clear for many so I went ahead and outlined a very simple three steps to getting remote packet captures with ROS done quick.
This post is meant to be a quick practical guide to help you capture traffic quickly for whatever your reasons may be. It can be a huge help with debugging network issues.

Step 1. Configure the packet sniffer tool on ROS to your target machine's IP address. You can change the port, just remember to set it in step 3.
mikrotik-wireshark-remote-capture-1.png

Step 2. In Wireshark, you should have an option for "UDP Listener remote capture", click the settings gear to configure the capture options
If you don't have this option then your problem is beyond this post and you need to reinstall Wireshark with udpdump.
mikrotik-wireshark-remote-capture-2.png

Step 3. Set the port to what you have set in ROS from step 1. If you changed the port from 37008, enter the new port number here.
I've set "tzsp" as the payload type so that the output from my capture rules will decode natively and show up as traffic is sent from ROS to Wireshark.
You will see traffic based on the rules of your capture in the ROS packet sniffer tool so remember to check your rules twice before starting the capture.
mikrotik-wireshark-remote-capture-3.png

Finally, you've got packets! Now, go forth and make debugging network issues easier.
If you have any issues or think I've missed something, please feel free to add to this thread. :)
mikrotik-wireshark-remote-capture-4.png
Note: This post is accurate as of ROS 7.1.1, Wireshark Version 3.6.1 (v3.6.1-0-ga0a473c7c1ba) and Npcap 1.60
You do not have the required permissions to view the files attached to this post.
Last edited by rfc1149 on Tue Jan 25, 2022 3:12 pm, edited 1 time in total.
 
msatter
Forum Guru
Forum Guru
Posts: 2912
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: Packet streaming from ROS and remote capture with Wireshark

Mon Jan 24, 2022 4:59 pm

Also available in Mangle:
Action - sniff-tzsp - send a packet to a remote TZSP compatible system (such as Wireshark). Set remote target with sniff-target and sniff-target-port parameters (Wireshark recommends port 37008)
https://help.mikrotik.com/docs/display/ ... ngle-Stats
 
User avatar
rfc1149
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 77
Joined: Fri May 15, 2020 4:26 am
Location: England

Re: Packet streaming from ROS and remote capture with Wireshark

Mon Jan 24, 2022 5:41 pm

Also available in Mangle:

I didn't even know about this! Thanks!
 
Sob
Forum Guru
Forum Guru
Posts: 9120
Joined: Mon Apr 20, 2009 9:11 pm

Re: Packet streaming from ROS and remote capture with Wireshark

Tue Jan 25, 2022 5:21 am

I use this old experiment of mine, and I'm very satisfied with it. I like that I see only captured packets, there's no unnecessary trace of TZSP.
 
User avatar
chechito
Forum Guru
Forum Guru
Posts: 3005
Joined: Sun Aug 24, 2014 3:14 am
Location: Bogota Colombia
Contact:

Re: Packet streaming from ROS and remote capture with Wireshark

Tue Jan 25, 2022 5:33 am

I use this old experiment of mine, and I'm very satisfied with it. I like that I see only captured packets, there's no unnecessary trace of TZSP.
very interesting i will give a try

Who is online

Users browsing this forum: Benzebub, LunaticRv, millenium7, natxo, spookymulder84 and 56 guests