<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA capture files not being read by Wireshark in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-capture-files-not-being-read-by-wireshark/m-p/1342054#M794878</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am still having difficulty "leveraging" with the "/pcap" parameter.  Where exactly in the copy command does it belong.  I have tried it everywher and the ASA is just not liking it...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Aug 2009 20:53:30 GMT</pubDate>
    <dc:creator>Kevin Melton</dc:creator>
    <dc:date>2009-08-20T20:53:30Z</dc:date>
    <item>
      <title>ASA capture files not being read by Wireshark</title>
      <link>https://community.cisco.com/t5/network-security/asa-capture-files-not-being-read-by-wireshark/m-p/1342052#M794876</link>
      <description>&lt;P&gt;I took some capture files this morning on our ASA appliance.  I actually view the packets being captured with the real time command.  Once I had what I needed, I ended the capture.  I then FTP the trace files to my workstation, opened Wireshark to then point to the files.  I keep getting this message when I try to open the files::The file "C:\FTProot\lori_ip" isn't a capture file in a format Wireshark understands.  I have tried using both a .pcap and a .cap extension.  I am still getting the same error message.&lt;/P&gt;&lt;P&gt;Wireshark is opening other files just fine.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:08:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-capture-files-not-being-read-by-wireshark/m-p/1342052#M794876</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2019-03-11T16:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA capture files not being read by Wireshark</title>
      <link>https://community.cisco.com/t5/network-security/asa-capture-files-not-being-read-by-wireshark/m-p/1342053#M794877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When transferring the capture files, you must be sure to leverage the '/pcap' parameter to copy the file as a valid *.pcap file.  You probably downloaded the file as the textual version.  You may still be able to glean some information from the file if you open it within a text viewer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also download the files leveraging the following URL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="https://" target="_blank"&gt;https://&lt;/A&gt;&lt;IP_ADDR&gt;/capture/&lt;CAPTURE_NAME&gt;/pcap&lt;/CAPTURE_NAME&gt;&lt;/IP_ADDR&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's a helpful link for the packet capture feature:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.nortfm.com/?View=entry&amp;amp;EntryID=1" target="_blank"&gt;http://www.nortfm.com/?View=entry&amp;amp;EntryID=1&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Aug 2009 20:39:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-capture-files-not-being-read-by-wireshark/m-p/1342053#M794877</guid>
      <dc:creator>Kevin Redmon</dc:creator>
      <dc:date>2009-08-20T20:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA capture files not being read by Wireshark</title>
      <link>https://community.cisco.com/t5/network-security/asa-capture-files-not-being-read-by-wireshark/m-p/1342054#M794878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am still having difficulty "leveraging" with the "/pcap" parameter.  Where exactly in the copy command does it belong.  I have tried it everywher and the ASA is just not liking it...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Aug 2009 20:53:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-capture-files-not-being-read-by-wireshark/m-p/1342054#M794878</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2009-08-20T20:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA capture files not being read by Wireshark</title>
      <link>https://community.cisco.com/t5/network-security/asa-capture-files-not-being-read-by-wireshark/m-p/1342055#M794879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using the capture command, the syntax would look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;copy /pcap capture:[context/]&lt;CAPTURE_NAME&gt; &lt;DESTINATION&gt;&lt;/DESTINATION&gt;&lt;/CAPTURE_NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a link to the command reference also:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/c4.html#wp2123161" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/c4.html#wp2123161&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Aug 2009 17:00:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-capture-files-not-being-read-by-wireshark/m-p/1342055#M794879</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2009-08-21T17:00:31Z</dc:date>
    </item>
  </channel>
</rss>

