interface=internal0
dt=$(hostname)_$interface__$(date +'%m_%d_%Y')
pcap_file='/tmp/packet_captures/'$dt'-pause_frames.pcap'
mgmt_filter='ether proto 0x8808 and ether[14:2] = 0x0001'
tshark -i $interface -n -f $mgmt_filter -w $pcap_file
Category: network_engineering
-
Capture Ethernet pause frames in Wireshark