ANNOUNCEMENT: Live Wireshark University & Allegro Packets online APAC Wireshark Training Session
July 17th, 2024 | 10:00am-11:55am SGT (UTC+8) | Online

Wireshark-users: [Wireshark-users] Capturing VLAN tags with Wireshark

From: Steve Bertrand <steve@xxxxxxxxxx>
Date: Thu, 10 Jul 2008 09:41:54 -0400
Hi everybody,

I've got a handful of VLANs (802.1q) running over a Cisco infrastructure and I'm trying to capture the Ethernet frames on a switch trunk port while retaining the VLAN information contained within.

From what I can tell, in order to be able to do a port monitor on a Catalyst switch to sniff VLAN traffic, I have to assign the monitor port as a switchport access within a specific VLAN. I assume that when I do it this way, the VLAN tag is being stripped off before the monitor port hands off the packet to Wireshark. Is this correct?

Am I missing something obvious? I'd just like to be able to monitor ALL traffic that is ingress/egress on a specific trunk port for all allowed VLANs on that trunk, all the while retaining the VLAN information within the frame.

Thanks for any advice.

Steve