<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Packet Capture in ASDM vs. CLI in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/packet-capture-in-asdm-vs-cli/m-p/1585294#M559195</link>
    <description>&lt;P&gt;Forum&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the features I have always loved on the ASA was the ability to use the packet capture.&amp;nbsp; If I remember correctly, I have been using this feature maybe since version 6.x in the PIX.&amp;nbsp; It has helped solve many network issues and questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We now of course have the feature in ASDM that allows Packet Capture also.&amp;nbsp; I have had a quesiton for a long time, but had not posted it as I dont often think of it.&amp;nbsp; Today I found myself working at a client site and was working with Packet Captures and ACL's, and it made me remember the question.&amp;nbsp; here goes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When building a capture on the CLI, we have some prerequites.&amp;nbsp; First we need an ACL to match for interesting traffic for the capture buffer.&amp;nbsp; Then we name the capture, and reference the ACL while applying to an interface.&amp;nbsp; This is all we need to do to get the capture up and running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When building a capture on the ASDM, we have some options for building out just like in CLI.&amp;nbsp; You can pick whatever ACL you want to use that ASDM sees configured on the box, or you can "Manage" the ACL's ( and I guess create a new one) by hitting the "Manage" button. &lt;/P&gt;&lt;P&gt;The one thing that is different is that the ASDM Packet Capture Wizard wants an "ingress" and "egress" interface for the Wizard.&amp;nbsp; There does not seem to be a way to only capture on one (1) interface in the Packet Capture Wizard in ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the question at hand would be "Can one use the ASDM Packet Capture Wizard and only assign one interface, and if so, how?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:12:12 GMT</pubDate>
    <dc:creator>Kevin Melton</dc:creator>
    <dc:date>2019-03-11T20:12:12Z</dc:date>
    <item>
      <title>Packet Capture in ASDM vs. CLI</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-in-asdm-vs-cli/m-p/1585294#M559195</link>
      <description>&lt;P&gt;Forum&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the features I have always loved on the ASA was the ability to use the packet capture.&amp;nbsp; If I remember correctly, I have been using this feature maybe since version 6.x in the PIX.&amp;nbsp; It has helped solve many network issues and questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We now of course have the feature in ASDM that allows Packet Capture also.&amp;nbsp; I have had a quesiton for a long time, but had not posted it as I dont often think of it.&amp;nbsp; Today I found myself working at a client site and was working with Packet Captures and ACL's, and it made me remember the question.&amp;nbsp; here goes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When building a capture on the CLI, we have some prerequites.&amp;nbsp; First we need an ACL to match for interesting traffic for the capture buffer.&amp;nbsp; Then we name the capture, and reference the ACL while applying to an interface.&amp;nbsp; This is all we need to do to get the capture up and running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When building a capture on the ASDM, we have some options for building out just like in CLI.&amp;nbsp; You can pick whatever ACL you want to use that ASDM sees configured on the box, or you can "Manage" the ACL's ( and I guess create a new one) by hitting the "Manage" button. &lt;/P&gt;&lt;P&gt;The one thing that is different is that the ASDM Packet Capture Wizard wants an "ingress" and "egress" interface for the Wizard.&amp;nbsp; There does not seem to be a way to only capture on one (1) interface in the Packet Capture Wizard in ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the question at hand would be "Can one use the ASDM Packet Capture Wizard and only assign one interface, and if so, how?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:12:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-in-asdm-vs-cli/m-p/1585294#M559195</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2019-03-11T20:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Capture in ASDM vs. CLI</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-in-asdm-vs-cli/m-p/1585295#M559202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer to this document for details:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml#configurationPACKETCAP"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml#configurationPACKETCAP&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Please reply back if you need more info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chirag&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this post as answered if you feel your query is resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Mar 2011 03:59:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-in-asdm-vs-cli/m-p/1585295#M559202</guid>
      <dc:creator>csaxena</dc:creator>
      <dc:date>2011-03-25T03:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Capture in ASDM vs. CLI</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-in-asdm-vs-cli/m-p/1585296#M559204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I already had that manual. The reason I had posted the question out to this Forum was due to the fact that in the manual, it only discusses using an Ingress and egress interface.&amp;nbsp; That is why I posted what I posted. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do appreciate you throwing the manual back to me though.&amp;nbsp; I am still looking for the answer to my original question, which is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can Packet Capture in the ASDM be used with only an Ingress or Egress (and NOT both) like it can be in CLI?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2011 15:32:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-in-asdm-vs-cli/m-p/1585296#M559204</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2011-04-11T15:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Capture in ASDM vs. CLI</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-in-asdm-vs-cli/m-p/1585297#M559206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I myself am a huge fan of the CLI for taking captures and for troubleshooting as well.&lt;/P&gt;&lt;P&gt;However, we generally do apply captures on two interfaces, to see the packet entering, and packet leaving the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried capturing using only ingress interface on the ASDM, but i don't think that would be possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The good thing though is that it applies two different captures, and does not combine the ingress and egress parameters.&lt;/P&gt;&lt;P&gt;So essentially, the packet capture wizard is allowing you to setup two separate captures on two separate interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do agree, that sometimes we use captures only on one interface just to see if a particular traffic is even reaching the ASA or not.&lt;/P&gt;&lt;P&gt;Unfortunately, I think all we can do in the ASDM for this scenario, is to ignore the parameters in the egress interface screen, and the captured packets that follow. A better configuration would be to configure traffic for the egress interface, which is not expected at all, so we don't see unnecessary data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shrikant&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2011 18:22:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-in-asdm-vs-cli/m-p/1585297#M559206</guid>
      <dc:creator>Shrikant Sundaresh</dc:creator>
      <dc:date>2011-04-11T18:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Capture in ASDM vs. CLI</title>
      <link>https://community.cisco.com/t5/network-security/packet-capture-in-asdm-vs-cli/m-p/1585298#M559207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shrikant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for taking the time to submit such a thorough answer.&amp;nbsp; This is what I had been looking for.&amp;nbsp; You have provided me with a sanity check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2011 18:50:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/packet-capture-in-asdm-vs-cli/m-p/1585298#M559207</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2011-04-11T18:50:13Z</dc:date>
    </item>
  </channel>
</rss>

