Hello all,
I was doing some captures on an ingress ASA and an egress ASA during testing at my company and encountered something strange. While we were testing, the captures I had configured (verified as correct by two of my senior engineers) weren't capturing any traffic. Yet, at the same time, a "sh conn | i x.x.x.x" showed the established TCP connection. The captures ended up showing packets from the test a whole 2 hours after they were configured, without us changing anything in the configuration. Would there be any reason for ASA packet captures to delay logging packets in the buffers?
Thank you in advance for any answers.