06-23-2016 07:48 AM - edited 03-12-2019 12:56 AM
Hi,
Running a pcap on ASA. If I have the folowing as an example -
capture CAP_Voice_LAN access-list ACL_Voice buffer 33554432 interface LAN circular-buffer
Will this capture packets in both directions? Entering the LAN interface and Leaving the LAN Interface or is unidirectional?
Thanks
06-23-2016 09:04 AM
Hi,
It depends on the access-list you link with the capture.
We need to define traffic bi-directionally.
access-list test permit
access-list test permit
This ACL would ensure that traffic is captured in both the directions.
capture CAP_Voice_LAN access-list test buffer 33554432 interface LAN circular-buffer
Regards,
Aditya
Please rate helpful posts and mark correct answers.
06-23-2016 08:11 PM
per my notes here:
By default, all packets moving through all ASA interfaces are captured. You should try to narrow the scope of the captured packets as much as possible so that only packets of interests are captured. You canspecify the ASA interface name where the capture should take place.
see also this helpful link:
http://ccnpsecuritywannabe.blogspot.com/2014/01/using-packet-capture-on-asa.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide