08-17-2008 09:04 AM - edited 03-11-2019 06:32 AM
Hi,
What troubleshooting steps are required to see if the traffic is passing from a specific host from internal network to DMZ or from outside to inside...
08-17-2008 10:51 AM
Hi,
A good step would be to go through the traffic logs.
However, if you dont want to go for logging/ syslog, these commands can be helpfull...
- "show access-list" >> to check the access-list hit count for that traffic.
- "show connection" >> to verify the entries in the connection table for your interesting traffic.
- "show xlate" >> to verify the entries in the NAT transalation table , whether correct NAT is configured or not.
08-17-2008 04:24 PM
You can also use ASDM and filter the interesting traffic.
08-17-2008 06:49 PM
If you would capture traffic for VPN.
If you would capture traffic for specific source and destination:
http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807c35e7.shtml
Configure above captures.
Thanks,
Dharmesh Purohit
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide