Category: network_engineering

  • Capture Ethernet pause frames in Wireshark

    interface=internal0
    dt=$(hostname)_$interface__$(date +'%m_%d_%Y')
    pcap_file='/tmp/packet_captures/'$dt'-pause_frames.pcap'
    mgmt_filter='ether proto 0x8808 and ether[14:2] = 0x0001'
    tshark -i $interface -n -f $mgmt_filter -w $pcap_file