?
Solved

Packet capture on ASA 7.x cli

Posted on 2013-05-26
3
Medium Priority
?
641 Views
Last Modified: 2013-05-28
Hi,

How can I initiate a capture packet on an ASA 7x firewall using the CLI? I'm struggling with this for hours now and I seem to be lost somewhere.

I need to capture data that originates from inside host 10.31.3.103 to outside host 213.55.147.20 > TCP/2000.

Any help would be very appreciated!
0
Comment
Question by:OrcaGroup
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 17

Assisted Solution

by:max_the_king
max_the_king earned 400 total points
ID: 39198924
Hi,

try the following, create an access-list that permits that traffic, e.g.:

access-list capture_list permit tcp host 10.31.3.103 host 213.55.147.20 eq 2000
access-list capture_list permit tcp host  213.55.147.20 eq 2000 host 10.31.3.103

capture  capture_list access-list  capture_list interface inside

hope this helps
max
0
 
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 800 total points
ID: 39199365
Is this the problem you are trying to troubleshoot?

Cannot Connect to TCP Port 2000 (Even over VPN)
Pete
0
 
LVL 18

Accepted Solution

by:
Garry Glendown earned 800 total points
ID: 39200580
Just an addendum to Max' comment ...  I'd always run the capture on both sides of the firewall, also adding a buffer size and increasing the packet size in case you need to look into what actually is happening inside the packets can occasionally help, so:

capture INSIDEDATA access capture_list int inside buf 1024000 packet-length 1500
capture OUTSIDEDATA access capture_list int outside buf 1024000 packet-length 1500

Please note that you may need to extend the access list to match the outside NAT IP of the internal box.

Once you have the capture running, check with "show capture" to see whether any packets have been captured, or "show capture INSIDEDATA" to see what packets have been transfered ... or use the web interface with "https://ASA_IP/capture/INSIDEDATA/pcap" to download a Wireshark-compatible PCAP dump for further analysis ...
0

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
Let’s face it: one of the reasons your organization chose a SaaS solution (whether Microsoft Dynamics 365, Netsuite or SAP) is that it is subscription-based. The upkeep is done. Or so you think.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question