<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The best way to find out if in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-packet-capture/m-p/2970201#M149907</link>
    <description>&lt;P&gt;The best way to find out if it's ASA issue or not using capture, is to run 2 capture commands. One on the inbound interface and one on the outbound. If traffic is working fine, you should see incoming &amp;amp; outgoing packets on both captures. If you see packets leaving but nothing is coming back, then it's not an ASA issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;capture cap1 interface x match ip host a host b&lt;/P&gt;
&lt;P&gt;capture cap2 interface y match ip host a host b&lt;/P&gt;
&lt;P&gt;show cap cap1&lt;/P&gt;
&lt;P&gt;show cap cap2&lt;/P&gt;</description>
    <pubDate>Sun, 18 Sep 2016 03:02:20 GMT</pubDate>
    <dc:creator>Hozaifa Samad</dc:creator>
    <dc:date>2016-09-18T03:02:20Z</dc:date>
    <item>
      <title>ASA packet capture</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-capture/m-p/2970200#M149906</link>
      <description>&lt;P&gt;Dears ,&lt;/P&gt;
&lt;P&gt;Topology.&lt;/P&gt;
&lt;P&gt;DMZ -Zone-&amp;gt;&amp;gt;&amp;gt;ASA firewall&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;Internet router&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ISP&lt;/P&gt;
&lt;P&gt;Please find the attached files and please explain me&amp;nbsp;from where the packets are getting&amp;nbsp;dropped&lt;/P&gt;
&lt;P&gt;I am trying to connect from a PC which is connected on internet router gig0/1 which is trying to access the OWA&amp;nbsp;server through&amp;nbsp;https OWA&amp;nbsp;link&amp;nbsp;,&amp;nbsp;OWA is on DMZ zone of the firewall, GIG0/0 of internet router is connected to Firewall Outside interface and the OWA is static natted on the firewall with public ip address.&lt;/P&gt;
&lt;P&gt;Router ADSL interface Public IP&amp;nbsp;Address: 82.82.82.189&lt;/P&gt;
&lt;P&gt;Static Natted&amp;nbsp;OWA server: 200.200.200.200.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;elaborating the connection how it is happening&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;PC has private ip address and a public DNS 8.8.8.8&lt;/LI&gt;
&lt;LI&gt;pc request to OWA link &lt;A href="https://abc.com" target="_blank"&gt;https://abc.com&lt;/A&gt; , PC has a dns of 8.8.8.8 request goes out to DNS and replies come of&amp;nbsp;OWA public IP address&lt;/LI&gt;
&lt;LI&gt;OWA public ip address&amp;nbsp;, firewall outside interface and Internet router internal interface&amp;nbsp;all in same public ip subnet.&lt;/LI&gt;
&lt;LI&gt;The page does not open on user PC.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;is it the DNS doctoring has to be done for the static nat of the OWA server.???????&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:17:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-capture/m-p/2970200#M149906</guid>
      <dc:creator>jack samuel</dc:creator>
      <dc:date>2019-03-12T08:17:07Z</dc:date>
    </item>
    <item>
      <title>The best way to find out if</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-capture/m-p/2970201#M149907</link>
      <description>&lt;P&gt;The best way to find out if it's ASA issue or not using capture, is to run 2 capture commands. One on the inbound interface and one on the outbound. If traffic is working fine, you should see incoming &amp;amp; outgoing packets on both captures. If you see packets leaving but nothing is coming back, then it's not an ASA issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;capture cap1 interface x match ip host a host b&lt;/P&gt;
&lt;P&gt;capture cap2 interface y match ip host a host b&lt;/P&gt;
&lt;P&gt;show cap cap1&lt;/P&gt;
&lt;P&gt;show cap cap2&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2016 03:02:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-capture/m-p/2970201#M149907</guid>
      <dc:creator>Hozaifa Samad</dc:creator>
      <dc:date>2016-09-18T03:02:20Z</dc:date>
    </item>
    <item>
      <title>Dear Hozaifa,</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-capture/m-p/2970202#M149908</link>
      <description>&lt;P&gt;Dear Hozaifa,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have one doubt, when the reply&amp;nbsp;goes back the packets will travel the outside interface so why we need to capture on&amp;nbsp;both the interfaces. ???&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 20:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-capture/m-p/2970202#M149908</guid>
      <dc:creator>jack samuel</dc:creator>
      <dc:date>2016-09-19T20:07:10Z</dc:date>
    </item>
    <item>
      <title>Hi Jack,</title>
      <link>https://community.cisco.com/t5/network-security/asa-packet-capture/m-p/2970203#M149909</link>
      <description>&lt;P&gt;Hi Jack,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm not clear on your question, but having captures on both interfaces will tell you if it's ASA or not ASA issue. For example if you see packing coming on inbound but not leaving outbound, then it's ASA issue. If packet coming on inbound, leaving the outbound but no return, then it's not ASA issue. Also, you can get a return on the outbound, but ASA doesn't send it back to the source, then it's ASA. Using 2 captures just to tell you what exactly is going on.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 20:17:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packet-capture/m-p/2970203#M149909</guid>
      <dc:creator>Hozaifa Samad</dc:creator>
      <dc:date>2016-09-19T20:17:43Z</dc:date>
    </item>
  </channel>
</rss>

