Capture Ethernet pause frames in Wireshark

interface=internal0
dt=$(hostname)_$interface__$(date +'%m_%d_%Y')
pcap_file='/tmp/packet_captures/'$dt'-pause_frames.pcap'
mgmt_filter='ether proto 0x8808 and ether[14:2] = 0x0001'
tshark -i $interface -n -f $mgmt_filter -w $pcap_file

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *