<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Sam, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/packet-capture-command-on-cisco-asa/m-p/3093379#M133320</link>
    <description>&lt;P&gt;Hi Sam,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When traffic is outbound that is from inside:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;packet-tracer input inside &lt;G class="gr_ gr_89 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="89" data-gr-id="89"&gt;icmp&lt;/G&gt;&amp;nbsp;&amp;lt;ip of inside host&amp;gt; 8 0 &amp;lt;ip of the outside host&amp;gt; detailed&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When traffic is inbound :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;packet-tracer input outside &lt;G class="gr_ gr_319 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling" id="319" data-gr-id="319"&gt;tcp&lt;/G&gt;&amp;nbsp;&amp;lt;any host from the outside&amp;gt; &amp;lt;random TCP Port&amp;gt; &amp;lt;mapped IP/NAT-IP&amp;gt; &amp;lt;port&amp;gt; detailed&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;packet-tracer input outside &lt;G class="gr_ gr_435 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="435" data-gr-id="435"&gt;tcp&lt;/G&gt; 4.2.2.2 7878 2.2.2.2 443 detailed&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So in the destination, you would typically use a NAT IP rather than the real IP.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Aug 2017 14:01:26 GMT</pubDate>
    <dc:creator>Aditya Ganjoo</dc:creator>
    <dc:date>2017-08-14T14:01:26Z</dc:date>
    <item>
      <title>Packet Capture command on cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-command-on-cisco-asa/m-p/3093378#M133319</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you guys please explain me..what is the best way to put the packet capture command on Cisco ASA.&lt;/P&gt;
&lt;P&gt;1.When the traffic is going from inside to outside (which interface would be the best to capture the traffic)..?&lt;/P&gt;
&lt;P&gt;2.When the traffic is going coming from outside to inside(which interface would be the best to capture the traffic)..?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The only reason I'm getting confused is because we do have NAT configuration on ASA sometimes and this makes me scratch my head.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I would really appreciate if you guys can please explain me this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Sam&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:49:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-command-on-cisco-asa/m-p/3093378#M133319</guid>
      <dc:creator>sambillings459</dc:creator>
      <dc:date>2019-03-12T09:49:15Z</dc:date>
    </item>
    <item>
      <title>Hi Sam,</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-command-on-cisco-asa/m-p/3093379#M133320</link>
      <description>&lt;P&gt;Hi Sam,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When traffic is outbound that is from inside:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;packet-tracer input inside &lt;G class="gr_ gr_89 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="89" data-gr-id="89"&gt;icmp&lt;/G&gt;&amp;nbsp;&amp;lt;ip of inside host&amp;gt; 8 0 &amp;lt;ip of the outside host&amp;gt; detailed&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When traffic is inbound :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;packet-tracer input outside &lt;G class="gr_ gr_319 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling" id="319" data-gr-id="319"&gt;tcp&lt;/G&gt;&amp;nbsp;&amp;lt;any host from the outside&amp;gt; &amp;lt;random TCP Port&amp;gt; &amp;lt;mapped IP/NAT-IP&amp;gt; &amp;lt;port&amp;gt; detailed&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;packet-tracer input outside &lt;G class="gr_ gr_435 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="435" data-gr-id="435"&gt;tcp&lt;/G&gt; 4.2.2.2 7878 2.2.2.2 443 detailed&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So in the destination, you would typically use a NAT IP rather than the real IP.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2017 14:01:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-command-on-cisco-asa/m-p/3093379#M133320</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2017-08-14T14:01:26Z</dc:date>
    </item>
    <item>
      <title>Hi Aditya,</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-command-on-cisco-asa/m-p/3093380#M133321</link>
      <description>&lt;P&gt;Hi Aditya,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for replying...&lt;/P&gt;
&lt;P&gt;Actually I'm looking for packet capture command for e.g.&lt;/P&gt;
&lt;P&gt;capture cap-in match tcp host 1.1.1.1 host 2.2.2.2 eq &amp;nbsp;80&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Sam&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2017 16:07:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-command-on-cisco-asa/m-p/3093380#M133321</guid>
      <dc:creator>sambillings459</dc:creator>
      <dc:date>2017-08-14T16:07:28Z</dc:date>
    </item>
    <item>
      <title>Hi Sam,</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-command-on-cisco-asa/m-p/3093381#M133322</link>
      <description>&lt;P&gt;Hi Sam,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My bad &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you need the packet capture for outbound traffic and inbound traffic you need to capture in both the directions:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Ingress capture:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;capture &lt;G class="gr_ gr_136 gr-alert gr_spell gr_inline_cards gr_disable_anim_appear ContextualSpelling ins-del multiReplace" id="136" data-gr-id="136"&gt;capin&lt;/G&gt; interface inside match &lt;G class="gr_ gr_169 gr-alert gr_spell gr_inline_cards gr_disable_anim_appear ContextualSpelling" id="169" data-gr-id="169"&gt;ip&lt;/G&gt; host &amp;lt;&amp;gt; host &amp;lt;&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This match statement is bi-directional.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In case there is NAT then you need to make a slight change.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Let's say you have a dynamic NAT for internet access for inside users and traffic is not working:&lt;/P&gt;
&lt;P&gt;Something like this:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;object-network obj-10.0.0.0&lt;/P&gt;
&lt;P&gt;subnet 10.0.0.0 255.255.255.0&lt;/P&gt;
&lt;P&gt;nat (inside,outside) dynamic 1.1.1.1&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;capture cap interface inside match &lt;G class="gr_ gr_663 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling" id="663" data-gr-id="663"&gt;tcp&lt;/G&gt; host 10.0.0.1 host 4.2.2.2 eq 80&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;capture capo interface outside match &lt;G class="gr_ gr_742 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling" id="742" data-gr-id="742"&gt;tcp&lt;/G&gt;&amp;nbsp;host 1.1.1.1 host 4.2.2.2 eq 80&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This would capture the traffic&amp;nbsp;on both the interfaces and you would know&amp;nbsp;in which direction the traffic is working or not.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2017 16:20:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-command-on-cisco-asa/m-p/3093381#M133322</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2017-08-14T16:20:00Z</dc:date>
    </item>
    <item>
      <title>Hi Aditya,</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-command-on-cisco-asa/m-p/3093382#M133323</link>
      <description>&lt;P&gt;Hi Aditya,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you for replying.. really appreciate your effort&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you please give me some good links to documents which would help me in understanding these things.&lt;/P&gt;
&lt;P&gt;Thanks again&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Sam&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2017 17:08:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-command-on-cisco-asa/m-p/3093382#M133323</guid>
      <dc:creator>sambillings459</dc:creator>
      <dc:date>2017-08-14T17:08:52Z</dc:date>
    </item>
    <item>
      <title>Hi Sam,</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-command-on-cisco-asa/m-p/3093383#M133324</link>
      <description>&lt;P&gt;Hi Sam,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here are some links:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118097-configure-asa-00.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://www.tunnelsup.com/packet-captures-on-cisco-asa/&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Aditya&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Please rate helpful and mark correct answers&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 04:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-command-on-cisco-asa/m-p/3093383#M133324</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2017-08-15T04:17:42Z</dc:date>
    </item>
  </channel>
</rss>

