

Select CAPWAP under the protocol section & you will see something below. To avoid this you have to tick the following option in Wireshark.

But you will notice it appeared as ” Malformed Packet” at cannot see what’s inside this capwap packet. You can see it is a CAPWAP packet by using the destination port ( UDP 5247 for capwap-data & UDP 5246 for capwap-control). Monitor session 2 destination interface Fa1/0/10 Monitor session 2 source interface Fa1/0/2

How do you to see the CAPWAP encapsulated packets (AP WLC in controller based wireless deployment) using a wireshark ?īy default if you span the port connected to Light Weight Access point (in my case fa1/0/2) into another switchport (Fa1/0/10) by using the following CLI commands on the swtich, you will see something below in the screen.
