<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM and capture. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-and-capture/m-p/1551456#M605390</link>
    <description>&lt;P&gt;Another question about FWSM with software 4.1(1).&lt;/P&gt;&lt;P&gt;Using capture, we are able to view the captured packets after a minute, or more, that they hit the interface.&lt;/P&gt;&lt;P&gt;Why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Andrea&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:17:08 GMT</pubDate>
    <dc:creator>andrea.meconi</dc:creator>
    <dc:date>2019-03-11T19:17:08Z</dc:date>
    <item>
      <title>FWSM and capture.</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-capture/m-p/1551456#M605390</link>
      <description>&lt;P&gt;Another question about FWSM with software 4.1(1).&lt;/P&gt;&lt;P&gt;Using capture, we are able to view the captured packets after a minute, or more, that they hit the interface.&lt;/P&gt;&lt;P&gt;Why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Andrea&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:17:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-capture/m-p/1551456#M605390</guid>
      <dc:creator>andrea.meconi</dc:creator>
      <dc:date>2019-03-11T19:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM and capture.</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-capture/m-p/1551457#M605391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrea,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mean that it takes a minute or so before you see any packets show up in the capture you configured? If so, this is expected when you configure a new ACL to be used with a capture. The capture will not start showing packets until the ACL used to match the traffic is finished compiling.Therefore, the longer it takes for the ACLs to compile, the longer it will be before you start seeing any data in your capture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 14:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-capture/m-p/1551457#M605391</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-12-01T14:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM and capture.</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-capture/m-p/1551458#M605392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are right Mike.&lt;BR /&gt;But this happens with an ACL with two entries also?&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Andrea&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 14:36:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-capture/m-p/1551458#M605392</guid>
      <dc:creator>andrea.meconi</dc:creator>
      <dc:date>2010-12-01T14:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM and capture.</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-capture/m-p/1551459#M605393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrea,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, unfortunately all of the rules need to be recompiled whenever an ACL change is made. Therefore, this is expected behavior if you have a large set of ACLs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 14:42:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-capture/m-p/1551459#M605393</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-12-01T14:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM and capture.</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-capture/m-p/1551460#M605394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for your help Mike.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Andrea&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 14:47:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-capture/m-p/1551460#M605394</guid>
      <dc:creator>andrea.meconi</dc:creator>
      <dc:date>2010-12-01T14:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM and capture.</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-and-capture/m-p/1551461#M605395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry Mike. To be clear, FWSM captures all packets but shows these after some minutes, when session is already closed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 14:56:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-and-capture/m-p/1551461#M605395</guid>
      <dc:creator>andrea.meconi</dc:creator>
      <dc:date>2010-12-01T14:56:14Z</dc:date>
    </item>
  </channel>
</rss>

