Kunbus TAP-2100 Reference guide

Ethernet Test Access Point
KUNBUS TAP-2100
Brief Instruction

KUNBUS GmbH
2KUNBUS Ethernet Test Access Point TAP-2100
© 2015 KUNBUS GmbH, Denkendorf (Deutschland)
The contents of this user manual have been prepared by the KUNBUS GmbH with the
utmost care. Due to the technical development, the KUNBUS GmbH reserves the right
to change or replace the contents of this user manual without prior notice. You can
always obtain the latest version of the user manual at our homepage: www.kunbus.
com.
The KUNBUS GmbH shall be liable exclusively to the extent specified in General Terms
and Conditions (www.kunbus.de/agb.html).
The contents published in this user manual are protected by copyright. Any reproduction
or use for the in-house requirements of the user is permitted. Reproduction or use for
other purposes are not permitted without the express, written consent of the KUNBUS
GmbH. Contraventions shall result in compensation for damages.
Trademark protection
• KUNBUS is a registered trademark of the KUNBUS GmbH
• Windows® and Microsoft® are registered trademarks of the Microsoft, Corp.
• Modbus is a registered trademark of the Modbus-IDA Organization.
KUNBUS GmbH
Heerweg 15 c
73770 Denkendorf
Germany
www.kunbus.com

3
KUNBUS GmbH KUNBUS Ethernet Test Access Point TAP-2100
Table of Content
Safety............................................................................................5
Qualified personnel...................................................................................5
Intended Use..............................................................................................5
Symbols......................................................................................................5
Safety instructions to prevent damage to property and
personal injuries........................................................................................6
Limitation of Liability ...............................................................................7
Introduction..................................................................................8
Scope of delivery.......................................................................................8
Areas of use...............................................................................................8
Technical data:...........................................................................................9
General data...............................................................................................9
Operation....................................................................................10
Installation................................................................................................10
Operation with Wireshark.......................................................................11
Wireshark principles..............................................................................11
Wireshark installation ............................................................................11
Starting a Wireshark capture.................................................................12
Wireshark-Statusfenster........................................................................13
Troubleshooting.....................................................................................15
Errata..........................................................................................16

KUNBUS GmbH
4KUNBUS Ethernet Test Access Point TAP-2100

5
KUNBUS GmbH KUNBUS Ethernet Test Access Point TAP-2100
1 Safety
1.1 Qualified personnel
The TAP2110 may only be assembled, installed and put into operation by trained,
qualified personnel. Before assembly, it is absolutely essential that this documentation
has been read carefully and understood. Expertise in the following fields is assumed:
• Evaluation of the security of electrical equipment
• Installing and Configuring IT systems
• Measuring and analyzing electrical functions and systems
• Safety and health at work
• Assembly and connection of electrical equipment
• Locally applicable rules and regulations for occupational safety.
1.2 Intended Use
The TAP-2110 is made for analysis of ethernet based data flow.
1.3 Symbols
The symbols used have the following meaning:
Symbol Bezeichnung Bedeutung
Hazard
Observe this information without fail!
There is a safety hazard that can lead to
serious injuries and death.
Caution
There is a safety hazard that can result in
minor injuries and material damage.
Note
There is a safety hazard that can result in
material damage.

KUNBUS GmbH
6KUNBUS Ethernet Test Access Point TAP-2100
1.4 Safety instructions to prevent damage to property and
personal injuries
The following safety instructions and warnings are intended to avert hazards and to
prevent damage to property and personal injuries.
Hazard
Improper handling or opening the housing can result in electric shock.
Caution
Only use the TAP-2110 with the supply voltage of 24V DC ±5 %.
Using other voltages result in damages or faults.
Caution
Only use the the specified signaling voltage. Operation with a
signaling voltage other than the specified signaling voltage may lead
to severe damage to the TAP-2110.
Caution
Only use the bunch plugs/banana plugs with design laboratory
apparatus.Don`t plug the bunch plugs/banana plugs in to a
conventional socket.
Note
Only work on a place which is shielded against electrostatic charge
Note
Store the TAP-2110 in the storage case.

7
KUNBUS GmbH KUNBUS Ethernet Test Access Point TAP-2100
1.5 Limitation of Liability
Warranty and liability claims will lapse if:
• the product has been used incorrectly,
• damage is due to non-observance of the operating manual,
• damage is caused by inadequately qualified personnel,
• damage is caused by technical modification to the product.

KUNBUS GmbH
8KUNBUS Ethernet Test Access Point TAP-2100
2 Introduction
With the KUNBUS-TAP 2100, KUNBUS makes a network monitor available for the
analysis of all current industrial ethernet solutions. Using four probe ports, this device
allows logging of up to two independent real-time ethernet connections. An internal
delay of 0 μs makes the KUNBUS-TAP Data Sniffer nearly transparent for the data
channels to be tested.
The Data-Sniffer is connected to a PC via a standard Gigabyte ethernet interface.
Network monitors read and analyze the tapped packet data, such as the freely available
„Wireshark“.
2.1 Scope of delivery
• Storage case
• TAP-2100
• Plastic cover
• Cable for power supply
• Euro Adapter
• Operating manual on USB-Stick (Present version at http://tap.kunbus.de)
• Wireshark plugins on USB-Stick (Present version at http://tap.kunbus.de)
2.2 Areas of use
• Measuring system for real-time Ethernet bus systems
• Number of Ethernet ports 4+1 (cutting of 2 lines)
• Uplink-Port: - 1 GBit/s 1000BASE-T Ethernet - RJ45 socket
• Probe Ports: - 100 MBit/s 100BASE-TX Ethernet - RJ45 port, full and half-
duplex
• Zero delay ~0 μs
• Resolution time stamp 1 ns
• Diagnostics: 3 LEDs
• Unfiltered forwarding of CRC errors

9
KUNBUS GmbH KUNBUS Ethernet Test Access Point TAP-2100
2.3 Technical data:
• Measuring system for real-time Ethernet bus systems
• Number of Ethernet ports 4+1 (cutting of 2 lines)
• Uplink-Port: - 1 GBit/s 1000BASE-T Ethernet - RJ45 socket
• Probe Ports: - 100 MBit/s 100BASE-TX Ethernet - RJ45 port, full and half-
duplex
• Zero delay ~0 μs
• Resolution time stamp 1 ns
• Diagnostics: 3 LEDs
• Unfiltered forwarding of CRC errors
2.4 General data
• Supply voltage 24 V DC ±20% or 230 V AC plug power supply
• Weight about 150 g
• Dimensions (W x H x D) about 100 mm x 150 mm x 40 mm
• Rubber lining as bumper
• Fold-out base
• Permissible ambient temperature range in operation 0 °C ... + 55 °C
• Permissible ambient temperature range in storage -25 °C ... + 85 °C
• Permissible relative humidity 95 %, no condensation
• EMC-tested
• Protection type IP 20
• CE authorization

KUNBUS GmbH
10 KUNBUS Ethernet Test Access Point TAP-2100
3 Operation
3.1 Installation
1. After taking the delivery, please check whether all items listed in Chapter
„1.1. Scope of delivery“are present.
2. Connect the device using the included power cable
3. The POWER LED lights
4. Laden Sie sich die Netzwerkanalyse-Software „Wireshark“ auf den PC
und installieren Sie sie. Sie finden Wireshark auf www.wireshark.org.
4. Download the Wireshark plugin DLL from the KUNBUS website, and
copy it to the Wireshark plugin directory(e. g.: C:\Programme\Wireshark\
plugins\1.10.2).
• 32-Bit-Version: tap32_xxxx.dll (Wireshark-Plugin WIN32)
• 64-Bit-Version: tap64_xxxx.dll (Wireshark-Plugin WIN64)
xxxx stands for the version of Wireshark.(z.B. 1.10.2)
5. Connect the TAP-2100 with the RJ45 cable to a Gigabyte Ethernet
interface of the PC.If the connection between PC and TAP is successful,
the X0 link LED lights up.
6. Plug the line to be tested into the probe ports. The two ports ‘Port 1’ and
‘Port 2’ are connected directly. Therefore a connection is also possible
when the TAP is turned off. If the TAP is on and the a connection is
established, the link LEDs will be on. Between the two Ports the TX
and RX pins are exchanged. If a 1:1 cable must be monitored it must
be connected to the TAP and the TAP must be connected to the other
device using a crossover cable. If the devices are Auto-MDI-X capable
no attention must be paid on the kind of cable.
7. Start Wireshark on the PC. The plug-in ‚TAP‘ must be
‚enabled‘ in the menu „Edit > Preferences > Protocols > TAP“.
8. In Wireshark, start data capture on the Gigabyte Ethernet interface used.
9. Now the data can be analyzed using Wireshark.

11
KUNBUS GmbH KUNBUS Ethernet Test Access Point TAP-2100
The TAP 2100 can also be used without a plugin or another Ethernet analysis program.
However, the 20 byte supplemental information attached by TAP 2100 to the Ethernet
package cannot be decoded. Furthermore, it may happen that a packet is displayed as
faulty, although it just cannot be fully decoded because of the suppl
3.2 Operation with Wireshark
3.2.1 Wireshark principles
Wireshark is a free and very popular analysis program for network communication
connections, and was previously known as Ethereal. The designation Wireshark is
composed of the words wire and shark. Wireshark is a so-called Network Sniffer, or a
Network stumbler software.
The tool, known also as data logger software, provides the opportunity to map the
data traffic of an interface (generally Ethernet TCP/IP) after or while capturing a data
packet. A clear, simplified data analysis is provided that can easily be understood from
the user side. This way there is an opportunity to examine individually captured data
packets, or to sort by specific contents. In addition to extracting for example images
(binary content), Wireshark can also process and prepare clear data flow statistics.
WinPcap allows transparent recording from the respective data traffic under Microsoft
Windows. Wireshark works on almost all platforms:
• Windows
• Mac OS X
• AIX
• BSD
• Linux
• Solaris
Merely a network card and TAP 2100 are necessary to use Wireshark.
3.2.2 Wireshark installation
As mentioned above, Wireshark can be used on nearly all current systems. However, at
the moment a plugin is only offered for Windows to display the TAP-2100 supplemental
information. For further questions, please contact our sales department.
If Wireshark is already installed, the Wireshark plugin DLL will only need to be
downloaded from the KUNBUS website and copied to the Wireshark plugin directory,
e.g. C:\Programs\Wireshark\plugin\1.10.2. Use file tap32_1.10.2.dll or tap64_1.10.2.dll,
depending on use of the 32 or the 64 bit Wireshark version.

KUNBUS GmbH
12 KUNBUS Ethernet Test Access Point TAP-2100
• 32-Bit-Version: tap32_xxxx.dll (Wireshark-Plugin WIN32)
• 64-Bit-Version: tap64_xxxx.dll (Wireshark-Plugin WIN64)
xxxx stands for the version of Wireshark.(z.B. 1.10.2)
Achten Sie darauf, dass Wireshark und das Plugin die gleiche Versionsummer haben.
3.2.3 Starting a Wireshark capture
The Wireshark dialog can be accessed via the menu selection Capture/Interfaces.
The dialog in turn shows, with all the corresponding IP addresses, the respectively
recognized network interfaces. Furthermore, it displays the number of total packets
transferred and the transfer per second. The details function exclusively available
under Windows can be used to call up additional information about the respective
interfaces. To start the capture, merely click the Capture button. A window will then
present the captured frames and their exact quantity.

13
KUNBUS GmbH KUNBUS Ethernet Test Access Point TAP-2100
3.2.4 Wireshark-Statusfenster
The Wireshark main window consists of 3 parts:
• packet list
• packet details
• packet raw data
3.2.4.1 The packet list
Here, all packets are displayed in chronological order. As soon as the KUNBUS TAP
Spy plugin is activated, the „Time“ column will display the more accurate TAP 2100
time stamp instead of the operating system time stamp.
It is possible to display TAP 2100 values in additional columns. For this purpose, select
the field type ‚Custom‘ in settings (Menu Edit/Preferences) under columns. Enter for
example ‚tap.port‘ as the field name. As soon as ‘tap.’ has been entered, all possible
values are displayed. A description is provided below. With ‚Add‘, a column can be
added. Using the mouse, the lines can be moved and thus change the order.
To specifically evaluate traces, Wireshark offers a filter function. This allows limiting the
display and analysis to those frames that are the most interesting. For example, with
the filter the incoming and outgoing data traffic of your own IP address can be observed.
An exclusive observation of the Ping command can be realized with Wireshark. Here
you can filter according to TAP additional information. With the filter expression ‚tap.
port==a‘, for example only packets are displayed that were received at TAP 2100

KUNBUS GmbH
14 KUNBUS Ethernet Test Access Point TAP-2100
3.2.4.2 Packet details
If the TAP plugin is activated and the ethernet packet was captured with TAP 2100,
then additional information is displayed on the bottom line in section „KUNBUS TAP
Spy“:
Anzeige Bedeutung
FCS Original test total
Channel Channel on which the data was captured.
• 1: top ports X1
• 2: bottom ports X2
Port „A“, „B“, „C“ oder „D“ indicates which port received the data.
• „A“:connecter X1, Port1
• „B“: connecter X1, Port2
• „C“: connecter X2, Port1
• „D“: connecter X2, Port2
Since most devices today support automatic crossover (MDIX), it
may happen that both devices switch over to MDIX and the display
of A/B is swapped. The same applies to C/D.
CRC Error The received packet has a faulty test total.
Alignment Error The packet is faulty
Timestamp The packet time stamp is in ns, since turning on the Sniffer.
However, this value can be ignored, since the normal operating
system time stamp is replaced by the TAP time stamp, as soon as
the plugin is activated.
The main frames main frames of Wireshark are divided into three
parts. The packet lists, packet details, and hexadecimal packet
display are found here. The menu selection Edit/Preferences can
be used to select a column in the packet list.
3.2.4.3 Packet raw data
This section shows the packet data hexadecimal and as ASCII-text.The last 20 bytes
in the packet were attached from TAP 2100.

15
KUNBUS GmbH KUNBUS Ethernet Test Access Point TAP-2100
4 Troubleshooting
No Link on the
Snifferports X1 or X2.
Between the ports ‘Port 1’ and ‘Port 2’ the TX and RX
pins are switched (crossover). There it is necessary to
use a crossover cable on one side of the sniffer if the
devices are not Auto-MDI-X capable.
Not all packets are
displayed in Wireshark.
If the TAP plug-in is not activated, a test sum error may
be displayed. This is due to the additional data TAP
2100 attaches to the packet and it can be ignored.
Wireshark does not
display big packets.
The TAP adds 20 Bytes additional information to the
packets. If a packet is already more than 1480 bytes
long the packet on the output port X0 will exceed the
maximal allowed length of the Ethernet standard and
the packet will be discarded by the network adapter.
To solve this a network adapter that support ‘Jumbo
Packets’ must be used and ‘Jumbo Packets’ must be
enabled in the driver settings.
Packets are displayed as
faulty.
If the TAP plug-in is not activated, a test sum error may
be displayed. This is due to the additional data TAP
2100 attaches to the packet and it can be ignored.
Wireshark displays
additional packets.
It may happen that the PC that runs Wireshark
transmits Broadcast on the interface being used. This is
prevented by disabling all elements (client for Microsoft
networks, internet protocol (TCP/IP), etc.) in the LAN
adapter properties under Windows.

KUNBUS GmbH
16 KUNBUS Ethernet Test Access Point TAP-2100
5 Errata
This chapter contains all known problems with the TAP-2110 (Revision SW0030R02)
up to 17th September 2015.
• The very first Ethernet frame sent on one of the lines observed by the
TAP-2110 after a restart of the device (i. e. TAP-2110 runs trough power up
sequence) will not be transmitted over the Gigabit-Port (Uplink) but will get
lost.
Table of contents