<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Method to periodically transfer packet captures from ASA? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/method-to-periodically-transfer-packet-captures-from-asa/m-p/2565012#M205415</link>
    <description>&lt;P&gt;Investigating an intermittent issue we have with one of our systems, I have set-up a packet capture to look at the traffic going through the firewall. &amp;nbsp;The problem is, because we have no way of knowing when the issue is going to occur, the buffer can fill up before the relevant traffic is captured. &amp;nbsp;Likewise, if I use "circular-buffer" to overwrite the buffer from the beginning when full, I have still ended up missing the traffic I'm interested in because it's been overwritten by the time I go to look at it!&lt;/P&gt;&lt;P&gt;So, does anyone have a method whereby I could regularly copy off the packet captures to a TFTP server whenever the capture is full? &amp;nbsp;(or at least on a regular basis so I can hopefully have as much of the traffic as possible captured and available to look back at?)&lt;/P&gt;&lt;P&gt;It can sometimes be weeks before the problem we are looking into becomes apparent so I don't want to have to manually transfer the packet captures each time.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Any suggestions would be appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:02:25 GMT</pubDate>
    <dc:creator>mitchen</dc:creator>
    <dc:date>2019-03-12T05:02:25Z</dc:date>
    <item>
      <title>Method to periodically transfer packet captures from ASA?</title>
      <link>https://community.cisco.com/t5/network-security/method-to-periodically-transfer-packet-captures-from-asa/m-p/2565012#M205415</link>
      <description>&lt;P&gt;Investigating an intermittent issue we have with one of our systems, I have set-up a packet capture to look at the traffic going through the firewall. &amp;nbsp;The problem is, because we have no way of knowing when the issue is going to occur, the buffer can fill up before the relevant traffic is captured. &amp;nbsp;Likewise, if I use "circular-buffer" to overwrite the buffer from the beginning when full, I have still ended up missing the traffic I'm interested in because it's been overwritten by the time I go to look at it!&lt;/P&gt;&lt;P&gt;So, does anyone have a method whereby I could regularly copy off the packet captures to a TFTP server whenever the capture is full? &amp;nbsp;(or at least on a regular basis so I can hopefully have as much of the traffic as possible captured and available to look back at?)&lt;/P&gt;&lt;P&gt;It can sometimes be weeks before the problem we are looking into becomes apparent so I don't want to have to manually transfer the packet captures each time.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Any suggestions would be appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:02:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/method-to-periodically-transfer-packet-captures-from-asa/m-p/2565012#M205415</guid>
      <dc:creator>mitchen</dc:creator>
      <dc:date>2019-03-12T05:02:25Z</dc:date>
    </item>
    <item>
      <title>I don't know of an easy way</title>
      <link>https://community.cisco.com/t5/network-security/method-to-periodically-transfer-packet-captures-from-asa/m-p/2565013#M205416</link>
      <description>&lt;P&gt;I don't know of an easy way to do it since ASA doesn't have Kron. I can think of a couple not-so-easy ways though:&lt;/P&gt;&lt;P&gt;From a NMS platform (CiscoWorks/LMS, Rancid maybe??) schedule a job to run every x minutes to dump the cap and redirect it to a tftp server or a local file&lt;/P&gt;&lt;P&gt;Even more ghetto, if you use a terminal app like SecureCRT that can run VBScripts, create a vbscript to do the same thing (periodically log in and dump the cap with a redirect)&lt;/P&gt;&lt;P&gt;There's probably an easier way, I tend to over-think simple issues &amp;gt;&amp;lt;&lt;/P&gt;&lt;P&gt;good luck!&lt;/P&gt;</description>
      <pubDate>Thu, 06 Nov 2014 21:41:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/method-to-periodically-transfer-packet-captures-from-asa/m-p/2565013#M205416</guid>
      <dc:creator>AJ Cruz</dc:creator>
      <dc:date>2014-11-06T21:41:55Z</dc:date>
    </item>
    <item>
      <title>Yeah, that's what I've ended</title>
      <link>https://community.cisco.com/t5/network-security/method-to-periodically-transfer-packet-captures-from-asa/m-p/2565014#M205417</link>
      <description>&lt;P&gt;Yeah, that's what I've ended up doing - just scripting a job to run daily and login to the ASA to run the commands to dump the file to my TFTP server. &amp;nbsp; Was hoping there might be a "cleaner" and simpler way to do it via the ASA itself but alas, it seems that's not the case. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the advice all the same!&lt;/P&gt;</description>
      <pubDate>Fri, 07 Nov 2014 17:23:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/method-to-periodically-transfer-packet-captures-from-asa/m-p/2565014#M205417</guid>
      <dc:creator>mitchen</dc:creator>
      <dc:date>2014-11-07T17:23:25Z</dc:date>
    </item>
  </channel>
</rss>

