Monday, January 5, 2009

Traffic Sniffer on PPPoE Interfaces

When you are investigating traffic on PPPoE enabled interfaces you need to use a special interface to debug packets. For example your WAN1 interface is connected to your ISP via PPPoE. If you simply use the "diag sniffer packet wan1" command all you see are PPPoE encapsulated packets but not the actual source or destination traffic.
To investigate the packets on the WAN1 interface before they are encapsulated use the "ppp0" (that's a zero) interface.

Example: "diag sniffer packet ppp0"

2 comments:

Unknown said...

YEs I can able to sniffe the pppoe packets but not able to view its authentication on that??

Unknown said...

replay me