While troubleshooting municipal staff 802.1X failures, a capture uses aggressive packet slicing and EAP payloads are truncated. What should the analyst change?
Select an answer to reveal the explanation.
Short Explanation
Slicing is great until you cut off the EAP story mid-sentence — auth troubleshooting needs the whole payload. Tiny snaplens and ping-only tests won't show why 802.1X failed.
Full Explanation
Packet slicing truncates frame payloads and can remove EAP methods, identities, and TLS-related content needed to diagnose enterprise authentication. Analysts should disable slicing or use a snap length large enough for the required payloads. ICMP to RADIUS and aggressive slicing that claims to preserve certificates are counterproductive.