01-11-2011 07:51 PM - edited 03-11-2019 12:34 PM
Hi all,
Is it possible to cap specific traffic eg ftp following through the asa5510 or pix firewall?
Pls advise, thks in advance.
01-11-2011 08:12 PM
You can create access-list that match on the FTP traffic, by default FTP control is on TCP/21 and FTP data depending on whether it is passive or active FTP, it will use/negotiate either TCP/20 or random ports.
I would suggest that you just configure ACL that match the source and destination ip address and apply that to your capture command.
01-12-2011 03:31 AM
Hi
CAP = Capture ?
CAP = Bandwith management ?
Either way both are possible.
Capture
http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml
Bandwith management
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a008084de0c.shtml
Good luck
HTH
01-12-2011 04:43 AM
To add to Jennifer's suggestion, here is an example of how to police traffic you want http://supportforums.cisco.com/docs/DOC-1230#Traffic_Policing_with_Prioritization
I hope it helps.
PK
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide