Specifications
Remotely Monitoring Traffic
RoamAbout Mobility System Software Configuration Guide A-15
Remotely Monitoring Traffic
Remotetrafficmonitoringenablesyoutosnoopwirelesstraffic,byusingaDistributedAPasa
sniffingdevice.TheAPcopies thesniffed802.11packetsandsendsthecopiestoanobserver,
whichistypicallyaprotocolanalyzersuchasEtherealorTethereal.
How Remote Traffic Monitoring Works
Tomonitorwirelesstraffic,anAPradiocomparestrafficsentorreceivedontheradiotosnoop
filtersappliedtotheradiobythenetworkadministrator.Whenan802.11packetmatchesall
conditionsinafilter,theAPencapsulatesthepacketinaTazmenSnifferProtocol(TZSP)packet
andsendsthe
packettotheobserverhostIPaddressesspecifiedbythefilter.TZSPusesUDPport
37008foritstransport.(TZSPwascreatedby ChrisWatersofNetworkChemistry.)
Youcanmapuptoeightsnoopfilterstoaradio.Afilterdoesnotbecomeactiveuntilyouenableit.
Filtersand
theirmappingsarepersistentandremainintheconfigurationfollowingarestart.
However,filterstateisnotpersistent.IftheswitchortheAPisrestarted,thefilterisdisabled.To
continueusingthefilter,youmustenableitagain.
Using Snoop Filters on Radios That Use Active Scan
Whenactivescanisenabledinaradioprofile,theradiosthatusetheprofileactivelyscanother
channelsinadditiontothedatachannelthatiscurrentlyinuse.Activescanoperatesonenabled
radiosanddisabledradios.Infact,usingadisabledradioasadedicatedscannerprovidesbetter
roguedetectionbecausetheradiocanspendmoretimescanningoneachchannel.
Whenaradioisscanningotherchannels,snoopfiltersthatareactiveontheradioalsosnoop
trafficontheotherchannels.Topreventmonitoringofdatafromotherchannels,usethechannel
optionwhenyouconfigure
thefilter,tospecifythechannelonwhichyouwanttoscan.
All Snooped Traffic Is Sent in the Clear
Trafficthatmatchesasnoopfilteriscopiedafteritisdecrypted.Thedecrypted(clear)versionis
senttotheobserver.
Best Practices for Remote Traffic Monitoring
•DonotspecifyanobserverthatisassociatedwiththeAPwherethesnoopfilterisrunning.
Thisconfigurationcausesanendlesscycleofsnooptraffic.
•IfthesnoopfilterisrunningonaDistributedAP,andtheAPusedaDHCPserverinitslocal
subnettoconfigureitsIP
information,andtheAPdidnotreceiveadefaultrouter(gateway)
addressasaresult,theobservermustalsobeinthesamesubnet.Withoutadefaultrouter,the
APcannotfindtheobserver.
•TheAPthatisrunningasnoopfilterforwardssnoopedpacketsdirectlytotheobserver.This
is
aone‐waycommunication,fromtheAPtotheobserver.Iftheobserverisnotpresent,the
APstillsend sthesnooppackets,whichusebandwidth.Iftheobserverispresentbutisnot
listeningtoTZSPtraffic,theobservercontinuouslysendsICMPerrorindicationsbacktothe
AP.These
ICMPmessagescanaffectnetworkandAPperformance.