<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't view all captured packets. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-view-all-captured-packets/m-p/2304382#M311203</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest copying the whole capture to your local computer and open it with Wireshark&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;copy /pcap capture:SFTP_TEST t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://x.x.x.x/SFTP_TEST.pcap"&gt;ftp://x.x.x.x/SFTP_TEST.pcap&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Oct 2013 11:48:47 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-10-10T11:48:47Z</dc:date>
    <item>
      <title>Can't view all captured packets.</title>
      <link>https://community.cisco.com/t5/network-security/can-t-view-all-captured-packets/m-p/2304381#M311202</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any command which allows to change number of displayed captured packets?&lt;/P&gt;&lt;P&gt;I have a following capture setup:&lt;/P&gt;&lt;P&gt;capture SFTP_TEST type raw-data access-list SFTP_TEST buffer 200000 interface inside circular-buffer [Capturing - 199102 bytes]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I issue command show capture &lt;SPAN style="font-size: 10pt;"&gt;SFTP_TEST I get:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1676543 packets captured&lt;/P&gt;&lt;P&gt;1...&lt;/P&gt;&lt;P&gt;2...&lt;/P&gt;&lt;P&gt;and so on&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;157 packets shown.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far I have tried:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show capture SFTP_TEST count 10000 &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;same result (only 157 are shown)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same when I try&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;show capture SFTP_TEST count 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;(always displays magic number 157)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a very similar capture setup on another firewall and I can view all packets without any problems.&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Any help will be much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Regards&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Mariusz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-view-all-captured-packets/m-p/2304381#M311202</guid>
      <dc:creator>Mariusz Bochen</dc:creator>
      <dc:date>2019-03-12T02:50:05Z</dc:date>
    </item>
    <item>
      <title>Can't view all captured packets.</title>
      <link>https://community.cisco.com/t5/network-security/can-t-view-all-captured-packets/m-p/2304382#M311203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest copying the whole capture to your local computer and open it with Wireshark&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;copy /pcap capture:SFTP_TEST t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://x.x.x.x/SFTP_TEST.pcap"&gt;ftp://x.x.x.x/SFTP_TEST.pcap&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 11:48:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-view-all-captured-packets/m-p/2304382#M311203</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-10T11:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Can't view all captured packets.</title>
      <link>https://community.cisco.com/t5/network-security/can-t-view-all-captured-packets/m-p/2304383#M311205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And also,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think your capture buffer is too small. Its 200KB and its filled already and the ASA is overwriting the old content because of &lt;STRONG&gt;"circular-buffer"&lt;/STRONG&gt;. This is why NOT every capture packet is in the capture as the buffer has been configured too small. I generally use the max size thats close to 33,5MB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 11:50:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-view-all-captured-packets/m-p/2304383#M311205</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-10T11:50:07Z</dc:date>
    </item>
    <item>
      <title>Can't view all captured packets.</title>
      <link>https://community.cisco.com/t5/network-security/can-t-view-all-captured-packets/m-p/2304384#M311207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;SPAN style="font-size: 10pt;"&gt;Jouni,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Thanks for replying.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;I though the same, but the confusing bit was different number of packets captured and number of packets displayed.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Looks like the “packet captured” shows total number of packets processed by the defined capture rather than packets in the buffer so it makes sense what you said.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;I have reconfigured this with the maximum 33554432 buffer and I’ll post the outcome in few days.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Mariusz&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 08:58:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-view-all-captured-packets/m-p/2304384#M311207</guid>
      <dc:creator>Mariusz Bochen</dc:creator>
      <dc:date>2013-10-11T08:58:33Z</dc:date>
    </item>
    <item>
      <title>Can't view all captured packets.</title>
      <link>https://community.cisco.com/t5/network-security/can-t-view-all-captured-packets/m-p/2304385#M311209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That worked. &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Many thanks!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 10:14:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-view-all-captured-packets/m-p/2304385#M311209</guid>
      <dc:creator>Mariusz Bochen</dc:creator>
      <dc:date>2013-10-11T10:14:37Z</dc:date>
    </item>
  </channel>
</rss>

