This site requires JavaScript. Please try again.

Network Monitoring and Troubleshooting for Dummies

Networks are complex. Your network performance management shouldn’t be!

Register to download a FREE copy

Wireshark Enhancements: AirPcap

Wireless packet capture solution for Wireshark and Cascade Pilot

"Out with the old, in with the 11n USB AirPcap Nx! Whether diagnosing enterprise wireless issues or picking a channel for my Grandma’s wifi, this adapter is my favorite. It looks cool, it’s light as a feather and (since it’s integrated with WinPcap) it works seamlessly with Wireshark."
—Larry Averitt, Intel Corporation, Mobility Group

The AirPcap family is an open, affordable and easy-to-deploy wireless packet capture solution for MS Windows environments. AirPcap captures full 802.11 data, management and control frames that can be viewed in Wireshark and Cascade Pilot, providing in-depth protocol dissection and analysis capabilities. AirPcap is available in three models: AirPcap Classic, AirPcap Tx and AirPcap Nx.

AirPcap

ModelAirPcap ClassicAirPcap TxAirPcap Nx
Full 802.11 Capture Yes Yes Yes
Wireshark Integration Yes Yes Yes
Multi-channel Monitoring
(requires 2+ adapters)
Yes Yes Yes
Packet Transmission No Yes Yes
External Antenna Connector No No Yes
Form Factor USB USB USB
Frequency Bands b/g b/g a/b/g/n
Purchase Now

For a more detailed comparison of features, please see the AirPcap Family data sheet.

The AirPcap driver Software License Agreement is a single-seat license. If you wish to purchase AirPcap online, click here. The purchase of AirPcap is subject to these standard terms and conditions of sale and license

AirPcap adapters offer an easy way to capture and analyze 802.11 wireless traffic as well as full integration with the popular Wireshark and Cascade Pilot network analysis tools. Three AirPcap models are available:
  • AirPcap Classic captures and analyzes low-level 802.11b/g wireless traffic, including control, management and data frames on a Windows workstation or laptop. Per packet information is also available, such as power, hardware timestamps and receive rate.
  • AirPcap Tx delivers all of the functionality of AirPcap Classic and, additionally, supports packet injection.
  • AirPcap Nx is a dual-band solution supporting packet capture and injection for 802.11n, 802.11a/b/g legacy modes, and the 4.9 GHz US public safety channels. It features 2 x 2 MIMO with two internal antennas, plus two integrated MC-Card connectors for optional external antennas to enhance performance in the most demanding environments.

All AirPcap adapters operate in a completely passive mode to capture all frames (data, control and management) that are transferred on a channel, not just frames that are addressed to them. When more than one BSS shares the same channel, the AirPcap adapter will capture frames from all BSSs that are sharing the channel within range of the AirPcap adapter. AirPcap adapters capture traffic on a single channel at a time; however, the channel setting can be easily changed to any valid 802.11 channel for packet capture. When used with Cascade Pilot, AirPcap can perform channel scans or lock onto multiple channels if 2 or more adapters are used.

AirPcap Classic
  • 802.11 b/g packet capture on 20MHz channels 
  • Detailed decoding of control, management and data frames in Wireshark, including A-MSDUs, A-MPDUs, and HT information 
  • Simultaneous multi-channel monitoring and capture when using multiple AirPcap adapters 
  • Exclusive multi-channel aggregation technology merges multiple trace files into a single file 
  • Per-packet radio information 
  • Wireshark and Cascade Pilot Personal Edition integration for complete WLAN traffic analysis, visualization, drill-down, and reporting 
  • USB host interface for portable, flexible deployment 
  • AirPcap and WinPcap APIs for creation or extension of your own 802.11 testing and diagnostic tools 
  • Support for any Windows OS from Windows 2000 to Windows 7, VMWare on a Macintosh or Linux machine, or a VM session within Windows 

AirPcap Tx delivers all of the functionality of AirPcap Classic and additionally supports:

  • 802.11 b/g packet replay/injection

AirPcap Nx delivers all of the functionality of AirPcap Classic and additionally supports:

  • Packet capture and injection for 802.11n, 802.11a/b/g legacy modes, the 4.9 GHz US Public safety channels and many non-standard 5GHz bands
  • Two internal antennas and two integrated MC-Card connectors for optional external antennas
  • Support for 2x2 MIMO
  • Microsecond-precision hardware time-stamping for roaming analysis.

Multiple Channel Capture: When monitoring on a single channel is not enough, multiple AirPcap adapters can be plugged into a laptop or a USB hub to provide simultaneous multi-channel capture and traffic aggregation. The AirPcap driver provides support for this operation through multi-channel aggregator technology that exports capture streams from two or more AirPcap adapters as a single capture stream. The multi-channel aggregator consists of a virtual interface that can be used from Wireshark or any other AirPcap-based application. Using this interface, the application will receive the traffic from all installed AirPcap adapters, as if it was coming from a single device. The multi-channel aggregator can be configured like any AirPcap device, and therefore can have its own decryption, FCS checking and packet filtering settings.

Transmit Raw 802.11 Frames: AirPcap Tx and Airpcap Nx can inject raw 802.11 frames into a wireless network, making them an invaluable aid in assessing wireless security. AirPcap Tx and AirPcap Nx can inject any kind of frame, including control, management and data frames. These frames can be transmitted at any allowable rate depending upon your adapter.

WEP Decryption: The AirPcap driver can be configured to decrypt WEP-encrypted frames. An arbitrary number of keys can be configured in the driver at the same time, enabling it to decrypt the traffic of more than one access point simultaneously. WPA and WPA2 support is handled by Wireshark.

AirPcap Control Panel with Multi-Channel Aggregator Option Selected

AirPcap Control Panel with Multi-Channel Aggregator Option Selected

Cascade Pilot Personal Edition deployed with 3 AirPcap adapters locked on to separate channels displaying bandwidth over time

Cascade Pilot Personal Edition deployed with 3 AirPcap adapters locked on to separate channels displaying bandwidth over time

Wireshark Wireless Toolbar with AirPcap Installed

Wireshark Wireless Toolbar with AirPcap Installed

Benefits
The AirPcap family provides superior capture performance with minimal packet loss for multi-channel capture on 802.11 networks. Integration with Wireshark and Cascade Pilot simplifies WLAN traffic analysis, visualiza­tion, drill-down, and reporting, accelerating root cause analysis for wireless environments. In addition, because AirPcap de-couples capture from analysis, it delivers added flexibility and better performance.

Learn More:

 

Other Related Content:

Sharkfest '12
Wireshark Developers & User Event
Dates, agendas, and retrospectives
Learn More

Media Feed RSS Twitter Facebook YouTube LinkedIn
Riverbed announces Cascade 9.5
Today, Riverbed announced Cascade 9.5 and Virtual Cascade Shark, which will provide customers with the needed visibility into load-balanced
More

Riverbed Connect Podcast - Cascade 9.5
Riverbed Connect Podcast - Cascade 9.5 Bob Gilbert sits down with Sr. Director of Product Management Dimitri Vlachos to discuss the 9.5
More

Riverbed Cascade Extends Network Visibility Deeper into the Data Center
Riverbed Cascade Extends Network Visibility Deeper into the Data Center
More

Introduction to Cascade Shark and Cascade Pilot
Produced by Riverbed Join us for a live, interactive demonstration of the powerful, unique features of Cascade Shark and Cascade Pilot
More

Jack Demo: Riverbed Cascade (Polish Subtitles)
Jack Demo: Riverbed Cascade (Polish Subtitles) From: RiverbedTechnology Views: 55 0 ratings Time: 05:54 More in Science &
More

Riverbed. WAN optimization for your network: Application acceleration, WAN bandwidth optimization, and IT consolidation
Riverbed Technology delivers performance for the globally connected enterprise. With Riverbed, enterprises can successfully and intelligently implement strategic initiatives such as virtualization, consolidation, cloud computing, and disaster recovery without fear of compromising performance. By giving enterprises the platform they need to understand, optimize and consolidate their IT, Riverbed helps enterprises to build a fast, fluid and dynamic IT architecture that aligns the business needs of the organization. Additional information about Riverbed (NASDAQ: RVBD) is available at www.riverbed.com.