Explains embedded packet capture as a feature for troubleshooting and monitoring network packet flows directly on Cisco devices.
An embedded packet capture is a network troubleshooting feature that
-
enables administrators to trace and analyze data packets in real time
-
allows capture of packets flowing through, to, and from a Cisco device, and
-
supports filtering, buffer management, and packet analysis for diagnosing complex network issues.
The Embedded Packet Capture on the controller is used for troubleshooting multiple issues, such as authentication failures with RADIUS, AP joining or disconnection, client forwarding, disconnection, and roaming. It can also help with specific features, including multicast, mDNS, Umbrella, and mobility. When troubleshooting an AP join or client onboarding issue, you might lose important information if you are unable to stop the capture immediately when the issue occurs. In most cases, a buffer of 100 MB is not sufficient for data capture. Moreover, the existing Embedded Packet Capture feature supports only the filtering of one inner MAC address, which captures the traffic of a specific client. At times, it is difficult to pinpoint which wireless client is experiencing an issue.
Beginning with Cisco IOS XE Dublin 17.12.1, the Embedded Packet Capture feature supports increased buffer size, continuous capture, and filtering of multiple MAC addresses in one session. You cannot configure the Embedded Packet Capture enhancement using the GUI.