<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861976#M167385</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Not sure but if I am doing it on my ASA I am able to filter it on the basis of subnet.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;May I know what is the &lt;G class="gr_ gr_155 gr-alert gr_gramm undefined Punctuation multiReplace" id="155" data-gr-id="155"&gt;requirement ?&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Mar 2016 11:51:53 GMT</pubDate>
    <dc:creator>Aditya Ganjoo</dc:creator>
    <dc:date>2016-03-16T11:51:53Z</dc:date>
    <item>
      <title>Cisco ASA ASP-DROP</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861973#M167382</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am trying to setup a capture using type asp-drop to capture dropped traffic between a internal network and an external network and I need to monitor the drop for 24hrs. I am using the commands&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;capture cap1 type asp-drop all&lt;/P&gt;
&lt;P&gt;match ip source subnet des subnet&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The capture just matches everything so does not filter down to the match statement.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What could I be doing wrong&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:29:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861973#M167382</guid>
      <dc:creator>Mokhalil82</dc:creator>
      <dc:date>2019-03-12T07:29:56Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861974#M167383</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It should only show you drops &lt;G class="gr_ gr_87 gr-alert gr_gramm undefined Grammar only-del replaceWithoutSep" id="87" data-gr-id="87"&gt;regarding to&lt;/G&gt; the matched subnets.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So what do you see except the defined &lt;G class="gr_ gr_86 gr-alert gr_gramm undefined Punctuation multiReplace" id="86" data-gr-id="86"&gt;subnets ?&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 11:17:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861974#M167383</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-16T11:17:28Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861975#M167384</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It filters the asp-drop type, for example if i configure "&lt;SPAN&gt;capture cap1 type asp-drop acl-drop"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But displays results for all ip ranges (everthing) that is being dropped because of reason acl-drop, not just for the source and destination subnets what I have defined in the match statement.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 11:34:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861975#M167384</guid>
      <dc:creator>Mokhalil82</dc:creator>
      <dc:date>2016-03-16T11:34:11Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861976#M167385</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Not sure but if I am doing it on my ASA I am able to filter it on the basis of subnet.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;May I know what is the &lt;G class="gr_ gr_155 gr-alert gr_gramm undefined Punctuation multiReplace" id="155" data-gr-id="155"&gt;requirement ?&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 11:51:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861976#M167385</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-16T11:51:53Z</dc:date>
    </item>
    <item>
      <title>We access an external service</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861977#M167386</link>
      <description>&lt;P&gt;We access an external service which is based on 2 subnets, and some users have reported random freezes when using this external service. I just want to run a asp-drop from all internal subnets to the 2 external subnets and see if the firewalls are dropping anything.&lt;/P&gt;
&lt;P&gt;I know the issue can be anywhere but just to ensure it is not the firewalls and to have some proof to say, ive got a capture running and it reports no drops, so the issue is elsewhere.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 12:09:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861977#M167386</guid>
      <dc:creator>Mokhalil82</dc:creator>
      <dc:date>2016-03-16T12:09:02Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861978#M167387</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Then the idea of having asp drop captures filtered on the subnets make sense.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You would also be interested in the &lt;G class="gr_ gr_65 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="65" data-gr-id="65"&gt;syslogs&lt;/G&gt; of the ASA at the time of the issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_153 gr-alert gr_gramm undefined Punctuation multiReplace" id="153" data-gr-id="153"&gt;Also&lt;/G&gt; can you try filtering on the basis of host IP's and see if you still see the same behaviour.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also, what ASA version are you &lt;G class="gr_ gr_179 gr-alert gr_gramm undefined Punctuation multiReplace" id="179" data-gr-id="179"&gt;running ?&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 12:44:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861978#M167387</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-16T12:44:23Z</dc:date>
    </item>
    <item>
      <title>Thanks Aditya</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861979#M167388</link>
      <description>&lt;P&gt;Thanks Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am running ASA version&amp;nbsp;9.1(6)6&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 12:58:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861979#M167388</guid>
      <dc:creator>Mokhalil82</dc:creator>
      <dc:date>2016-03-16T12:58:04Z</dc:date>
    </item>
    <item>
      <title>I may check with TAC, as the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861980#M167389</link>
      <description>&lt;P&gt;I may check with TAC, as the configuration for the captures is not complex, but instead not giving the desired results&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 12:59:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861980#M167389</guid>
      <dc:creator>Mokhalil82</dc:creator>
      <dc:date>2016-03-16T12:59:07Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861981#M167390</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes it would be a good idea to check with TAC but before &lt;G class="gr_ gr_150 gr-alert gr_gramm gr_disable_anim_appear undefined Punctuation only-ins replaceWithoutSep" id="150" data-gr-id="150"&gt;that&lt;/G&gt; you can try filtering the &lt;G class="gr_ gr_112 gr-alert gr_spell gr_disable_anim_appear undefined ContextualSpelling" id="112" data-gr-id="112"&gt;captures&lt;/G&gt; on the basis of host IP's and test.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2016 14:03:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-asp-drop/m-p/2861981#M167390</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-16T14:03:07Z</dc:date>
    </item>
  </channel>
</rss>

