cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
870
Views
0
Helpful
3
Replies

ASA - Troubleshooting Steps

Amin Shaikh
Level 1
Level 1

Hi,

What troubleshooting steps are required to see if the traffic is passing from a specific host from internal network to DMZ or from outside to inside...

3 Replies 3

Hi,

A good step would be to go through the traffic logs.

However, if you dont want to go for logging/ syslog, these commands can be helpfull...

- "show access-list" >> to check the access-list hit count for that traffic.

- "show connection" >> to verify the entries in the connection table for your interesting traffic.

- "show xlate" >> to verify the entries in the NAT transalation table , whether correct NAT is configured or not.

Tshi M
Level 5
Level 5

You can also use ASDM and filter the interesting traffic.

purohit_810
Level 5
Level 5

If you would capture traffic for VPN.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9a87.shtml

If you would capture traffic for specific source and destination:

http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807c35e7.shtml

Configure above captures.

Thanks,

Dharmesh Purohit

Review Cisco Networking for a $25 gift card