<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Capture Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/capture-question/m-p/1227668#M876944</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you know the destination ip, then create an adequate ACL and capture on outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example: webserver - 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list test permit ip any host 1.1.1.1&lt;/P&gt;&lt;P&gt;access-list test permit ip host 1.1.1.1 any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture test access-list test interface outside [trace detail]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Celio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Feb 2009 08:55:30 GMT</pubDate>
    <dc:creator>celiocarreto</dc:creator>
    <dc:date>2009-02-03T08:55:30Z</dc:date>
    <item>
      <title>Capture Question</title>
      <link>https://community.cisco.com/t5/network-security/capture-question/m-p/1227667#M876943</link>
      <description>&lt;P&gt;Gents,&lt;/P&gt;&lt;P&gt;&amp;lt;br /&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;br /&amp;gt;I have an intersting problem, my company is having timeout problems when accessing a particular web site - this site can be accessed through a standard ADSL conneciton. We have a PIX 515 OS 8.x at the front of our corporate network. &lt;/P&gt;&lt;P&gt;&amp;lt;br /&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;br /&amp;gt;My question is this:&lt;/P&gt;&lt;P&gt;&amp;lt;br /&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;br /&amp;gt;How can I capture the return http packet information on the outside interface, bearing in mind that the connection has already been established via the ACL on the inside interface.&lt;/P&gt;&lt;P&gt;&amp;lt;br /&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;br /&amp;gt;I need to try and establish if the original syn packet has recieved an syn-ack reply.&lt;/P&gt;&lt;P&gt;&amp;lt;br /&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;br /&amp;gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;lt;br /&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;br /&amp;gt;Rod &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:45:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/capture-question/m-p/1227667#M876943</guid>
      <dc:creator>rod.blackie</dc:creator>
      <dc:date>2019-03-11T14:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Capture Question</title>
      <link>https://community.cisco.com/t5/network-security/capture-question/m-p/1227668#M876944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you know the destination ip, then create an adequate ACL and capture on outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example: webserver - 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list test permit ip any host 1.1.1.1&lt;/P&gt;&lt;P&gt;access-list test permit ip host 1.1.1.1 any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture test access-list test interface outside [trace detail]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Celio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Feb 2009 08:55:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/capture-question/m-p/1227668#M876944</guid>
      <dc:creator>celiocarreto</dc:creator>
      <dc:date>2009-02-03T08:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Capture Question</title>
      <link>https://community.cisco.com/t5/network-security/capture-question/m-p/1227669#M876945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Celio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have got the information I require by carrying out the sh conn command, however the site I am havinf problems with is showing a saA flag - I understand that this flag indicates that the PIX is awaiting a response, does this mean that there could be an conflict with the web server IP address and one of the pix security features????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Feb 2009 09:30:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/capture-question/m-p/1227669#M876945</guid>
      <dc:creator>rod.blackie</dc:creator>
      <dc:date>2009-02-03T09:30:54Z</dc:date>
    </item>
  </channel>
</rss>

