le 22-11-2023 09:24 AM
Hello
is there a possibility to perform a replication of a port on a Cisco ASA (e.g. to archive a copy of the data)?
The monitor command to be used on other Cisco equipment is not existing on the ASA.
Best regards
Jörg
le 22-11-2023 09:27 AM
What model of ASA - you can use Packet capture to send over to remote :
If the old model with Switch port on it, you can use command - switchport monitor
le 22-11-2023 10:05 AM
Thank you for this fast answer. I use an ASA-5508-X.
Your link is explaining how to capture packages (mainly local in a buffer of the ASA) and to transfer this data later on.
What I search is to duplicate packages (no change of format, quasi realtime) and to send them to a second destination.
We use this for UDP packages. This is well working using a replicated port on a switch. The aim is to reduce the hardware using directly the ASA.
The switchport monitor command seems not to be available.
22-11-2023 09:39 AM - modifié 22-11-2023 09:39 AM
https://ultraconfig.com.au/blog/how-to-packet-capture-on-a-cisco-asa-firewall/
Check this' not real time is so hard to asa cpu.
Keep capture real-time as short ss possible.
MHM
le 22-11-2023 10:14 AM
Thank you. See above. This is not what we need. Sorry if I was not clear enough.
le 22-11-2023 10:31 AM
copy /pcap capture:pc-traffic-ssh tftp://<server-ip-address>
This copy pcap to server which then can show via wiresharke.
But I think you want real time monitoring.
I will check
MHM
le 23-11-2023 12:41 AM
Découvrez et enregistrez vos notes préférées. Revenez pour trouver les réponses d'experts, des guides étape par étape, des sujets récents et bien plus encore.
Êtes-vous nouveau ici? Commencez par ces conseils. Comment utiliser la communauté Guide pour les nouveaux membres
Parcourez les liens directs de la Communauté et profitez de contenus personnalisés en français