peter mackenzie @mackenziewifi · site 1. site 2. site 3. site 4. site 5. hq. dmz. wlan controller....

34
IT Professional Wi-Fi Trek 2016 Interpreting Protocol Trace Files Peter Mackenzie @mackenziewifi

Upload: others

Post on 27-Jun-2020

44 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

IT Professional Wi-Fi Trek 2016

Interpreting Protocol Trace FilesPeter Mackenzie@mackenziewifi

Page 2: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN
Page 3: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN
Page 4: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN
Page 5: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN
Page 6: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN
Page 7: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

IT Professional Wi-Fi Trek 2016

The Packets Never Lie!But often our interpretation of the packets do

Page 8: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

Agenda• Which channel?

• Which packets should be acknowledged?

• What do corrupted packets mean?

• How important is location?

• Where is my data?

• Getting the complete picture

Page 9: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

IT Professional Wi-Fi Trek 2016

Which channel?

Page 10: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

Where we see channel information?

Page 11: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

Channel Information – Beacon

Channel the packet was capture on

Channel the packet was transmitted on

Page 12: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

IT Professional Wi-Fi Trek 2016

Which packets should be acknowledged?

Page 13: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

CTS / ACK

Page 14: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

Client Troubleshooting

Page 15: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

Acknowledgment

Page 16: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

IT Professional Wi-Fi Trek 2016

What do corrupted packets mean?

Page 17: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

CRC Errors

Page 18: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

Retries tell a better story

Page 19: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

IT Professional Wi-Fi Trek 2016

How important is location?

Page 20: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN
Page 21: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN
Page 22: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

Capture location

Page 23: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

2-way traffic seen here

Only AP traffic seen here

Is there a problem?

Capture location

Page 24: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

IT Professional Wi-Fi Trek 2016

Where is my data?

Page 25: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

Missing Data

Duration time between CTS and Block Ack is an indication of the data transmission

No data

Page 26: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

MU-MIMO Data Exchange

MU Sounding Exchange

MU Data

Data Ack

Page 27: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

IT Professional Wi-Fi Trek 2016

Getting the complete picture

Page 28: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN
Page 29: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

Know your protocol, know your network

Site 3 Site 4 Site 5Site 1 Site 2

HQ DMZWLAN Controller

WLAN Controller WLAN ControllerVLAN 10

VLAN 101 VLAN 102 VLAN 103 VLAN 104 VLAN 105

VLAN 20

Site WLANsCorp VLAN 10Guest VLAN 99

VLAN 99

Page 30: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

Site 3 Site 4 Site 5Site 1 Site 2

HQ DMZWLAN Controller

WLAN Controller WLAN ControllerVLAN 10

VLAN 101 VLAN 102 VLAN 103 VLAN 104 VLAN 105

VLAN 20

Site WLANsCorp VLAN 10Guest VLAN 99

VLAN 99

Know your protocol, know your network

Page 31: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

Site 3 Site 4 Site 5Site 1 Site 2

HQ DMZWLAN Controller

WLAN Controller WLAN ControllerVLAN 10

VLAN 101 VLAN 102 VLAN 103 VLAN 104 VLAN 105

VLAN 20

VLAN 99

Each location provides a different view

Wireless CaptureDHCP Discover

……DHCP Discover

AP Capture – VAN 99DHCP Discover

……DHCP Discover

Controller Capture VLAN 99DHCP DiscoverDHCP Offer

Page 32: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

Site 3 Site 4 Site 5Site 1 Site 2

HQ DMZWLAN Controller

WLAN Controller WLAN ControllerVLAN 10

VLAN 101 VLAN 102 VLAN 103 VLAN 104 VLAN 105

VLAN 20

VLAN 99

Each location provides a different view

AP Capture – Filter: Dropped PacketsPacket 1:Time: 14:12:18.565600, Len: 324, 802.3, Proto: 0x0800, Vlan: 343, Priority: 0, Ingress: extvlan, vlan343, l3_off: 18, l4_off: 38DropReason: wireless client-to-client disallow(228)802.3: 00-04-96-35-01-87 > D8-BB-2C-30-09-68, 802.11p pri 0, 802.11q vlan 343, protocol 0x0800IPv4: 10.187.36.2 > 10.187.37.92, proto UDP, IPv4 length 306, DSCP 0, Id 0, DFUDP: ports 67 > 68, data length 286DHCP: Offer from 0.0.0.0 to D8-BB-2C-30-09-68 of 10.187.37.92/255.255.254.0

DropReason: wireless client-to-client disallow(228)

Page 33: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

Site 3 Site 4 Site 5Site 1 Site 2

HQ DMZWLAN Controller

WLAN Controller WLAN ControllerVLAN 10

VLAN 101 VLAN 102 VLAN 103 VLAN 104 VLAN 105

VLAN 20

VLAN 99

Each location provides a different view

Forwarding Database - Analsyis#more system:/proc/dataplane/bridge/fdb | grep 00-04-96-35-01-87[1259.0 key 3fe5] 00-04-96-35-01-87 vlan 343 -> Tunnel to 46.4A.B5.8C, 296 sec to live, wireless-clientwireless-client

Page 34: Peter Mackenzie @mackenziewifi · Site 1. Site 2. Site 3. Site 4. Site 5. HQ. DMZ. WLAN Controller. WLAN Controller. VLAN 10. VLAN 101. VLAN 102. VLAN 103. VLAN 104. VLAN 105. VLAN

IT Professional Wi-Fi Trek 2016

Thank you!