EPC - Cisco Embedded Packet Capture

Cisco’s Embedded Packet Capture (EPC) allows us to capture packets that flow to, through or from a router. It is an integrated feature on Cisco IOS devices and can be fully used and leveraged via the CLI of the device.

Captures are stored in the DRAM on the router itself. A summary or even a detailed view of the captured packets can be viewed. Because the DRAM is limited in size, packet captures are generally small in size, and will be erased after a reload of the device.

It is possible to export these packet captures to an external server as a packet capture (PCAP) file to be further analyzed using tools such as Wireshark.

EPC is a quick alternative to creating a comparatively elaborate setup with SPAN or RSPAN since no additional configurations are necessary.

Links:

https://forum.networklessons.com/t/cisco-embedded-packet-capture-epc/1206/34?u=lagapides

https://networklessons.com/cisco/ccie-routing-switching/cisco-embedded-packet-capture-epc