<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VACL - Asynchronous Data Capture? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vacl-asynchronous-data-capture/m-p/412948#M95909</link>
    <description>&lt;P&gt;What is the best way to configure a VACL for packet capture on a pair of switches running HSRP for a respective VLAN?  If you have the same VACL on both switches and a capture port on each connected to a different monitoring port on a Cisco IPS Appliance, isn't it possible for the Sensor not to see the whole traffic flow?  Would the sensor would view such flows as dropped packets?&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 09:31:05 GMT</pubDate>
    <dc:creator>rm2017</dc:creator>
    <dc:date>2019-03-10T09:31:05Z</dc:date>
    <item>
      <title>VACL - Asynchronous Data Capture?</title>
      <link>https://community.cisco.com/t5/network-security/vacl-asynchronous-data-capture/m-p/412948#M95909</link>
      <description>&lt;P&gt;What is the best way to configure a VACL for packet capture on a pair of switches running HSRP for a respective VLAN?  If you have the same VACL on both switches and a capture port on each connected to a different monitoring port on a Cisco IPS Appliance, isn't it possible for the Sensor not to see the whole traffic flow?  Would the sensor would view such flows as dropped packets?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:31:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vacl-asynchronous-data-capture/m-p/412948#M95909</guid>
      <dc:creator>rm2017</dc:creator>
      <dc:date>2019-03-10T09:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: VACL - Asynchronous Data Capture?</title>
      <link>https://community.cisco.com/t5/network-security/vacl-asynchronous-data-capture/m-p/412949#M95910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you use an appliance like a IPS-4240 or IPS-4255 that have more than one sniffing interface then you can connect one interface to the first switch, and connect a second interface to the second switch.&lt;/P&gt;&lt;P&gt;Configure the sensor to monitor both of the interfaces.&lt;/P&gt;&lt;P&gt;Configure each switch to span or VACL Capture the desired traffic to the port connected to the sensor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The single sensor will recieve packets from both switches, and monitor the traffic from both the switches.&lt;/P&gt;&lt;P&gt;So long as both the client and server traffic flows through one switch or the other or even client and one and server on the other you will be fine.  Assuming your VACL has also been configured to capture both the client and server traffic, or your span will span both tx and rx traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The sensor will combine the packets from the 1st switch (1st port) and the packets from the 2nd switch (2nd port) and treat the packets as if they are on the same network.&lt;/P&gt;&lt;P&gt;So if incoming client packets are on switch 1, and outgoing server packets are on switch 2; it will see both sets of packets and be able to reconstruct the complete TCP connection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2005 21:44:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vacl-asynchronous-data-capture/m-p/412949#M95910</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2005-06-28T21:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: VACL - Asynchronous Data Capture?</title>
      <link>https://community.cisco.com/t5/network-security/vacl-asynchronous-data-capture/m-p/412950#M95911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the "reconstruct of assymetric routed packets" a feature that is implemented as of a specific software release or general available for a while?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jul 2005 12:18:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vacl-asynchronous-data-capture/m-p/412950#M95911</guid>
      <dc:creator>g.raymakers</dc:creator>
      <dc:date>2005-07-08T12:18:36Z</dc:date>
    </item>
  </channel>
</rss>

