Friday, February 12, 2021

Help me capture layer 4 protocol information for VPN protocols with Wireshark

Hello everyone,

We have a widespread issue with Cisco Anyconnect at our organization that I believe is being caused by DTLS. However the senior staff at my organization does not have a vested interest in actually providing long term permanent solutions to problems and as an IT person and junior engineer handling these issues I refuse to accept there isn't a long term solution to this problem.

So I am trying to prove it, document it and solve it myself (which is fine). What I am struggling with here is that the connection will drop every few hours for me (more often for others) so I am going to run wireshark in the background until the drop happens.

Rather than collect massive amounts of data I am wondering if there's a way that I can monitor the just the protocol information of the VPN failing over to TLS?

Can someone help here I am not a Wireshark savant yet.



No comments:

Post a Comment