<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet Capturing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/packet-capturing/m-p/443485#M100098</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess I meant to type "a" not "and".  The 4235 plugs into a Catalyst 6509, but not sure that is relevant.  I am wondering only if the 4235 can do packet capturing based on an alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Aug 2005 16:41:50 GMT</pubDate>
    <dc:creator>b.bader</dc:creator>
    <dc:date>2005-08-09T16:41:50Z</dc:date>
    <item>
      <title>Packet Capturing</title>
      <link>https://community.cisco.com/t5/network-security/packet-capturing/m-p/443483#M100090</link>
      <description>&lt;P&gt;I see other postings asking about configuring capturing on the IDSM, but is it possible to do this with and IDS 4235?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:34:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capturing/m-p/443483#M100090</guid>
      <dc:creator>b.bader</dc:creator>
      <dc:date>2019-03-10T09:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Capturing</title>
      <link>https://community.cisco.com/t5/network-security/packet-capturing/m-p/443484#M100094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess you have missed out something here what is the other device??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Aug 2005 14:53:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capturing/m-p/443484#M100094</guid>
      <dc:creator>beth-martin</dc:creator>
      <dc:date>2005-08-09T14:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Capturing</title>
      <link>https://community.cisco.com/t5/network-security/packet-capturing/m-p/443485#M100098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess I meant to type "a" not "and".  The 4235 plugs into a Catalyst 6509, but not sure that is relevant.  I am wondering only if the 4235 can do packet capturing based on an alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Aug 2005 16:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capturing/m-p/443485#M100098</guid>
      <dc:creator>b.bader</dc:creator>
      <dc:date>2005-08-09T16:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Capturing</title>
      <link>https://community.cisco.com/t5/network-security/packet-capturing/m-p/443486#M100106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can set packet capture or ip logging on any signature.  If you connect to the IDS via the IDM interface you can navigate to the signature configuration mode which is nested under configuration - sensor engine - signature configuration mode - all signatures - and then chose which signature you would like to enable the packet capture on and choose edit.  You will be presented with a list of variables that you can change for that specific signature.  One of the variables is packet capture, set this to true to enable.  If you would like a log of traffic between the attacker and the victim you can enable ip logging for that signature.  Care should be taken when enabling ip logging on a large amount of signature as this could cause performance issues.  You might also want to limit the size of the ip logs if you use this signature other wise you might end up with pretty large log files.  Please let me know if you need any more clarification on the process.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Aug 2005 06:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capturing/m-p/443486#M100106</guid>
      <dc:creator>nhoover</dc:creator>
      <dc:date>2005-08-20T06:08:34Z</dc:date>
    </item>
  </channel>
</rss>

