04-24-2025 10:05 PM
Dear Team,
Can anyone help me to to find a cli command on cisco FTD, I want to know if someone trying to open a application from PC, then how to check source ip tying to which destination ip & port. Actually i forgot. Some commands are there like listening or monitor the source ip & at that time end user when trying to open application then on firewall we can check all details application ip details try to communicate.
04-24-2025 10:45 PM
@suryaaa try the command "system support firewall-engine-debug" you can filter on the source IP and see the communication.
04-24-2025 11:17 PM
after entering this command its asking "Please specify an Ip protocol ", when I put IPV4 then its show error invalid protocol IPV4. Please help
04-24-2025 11:22 PM
@suryaaa that is optional, you can leave it blank (just press enter). Just enter the client IP (source IP), it will also prompt for the client port, server IP and server port, which you can also leave blank as well if you just want to filter from source.
04-25-2025 06:30 AM
I enter source ip address & keep blank server ip address. but nothing is showing after 2 hours. from source ip many application opening but nothing is showing.
04-25-2025 06:58 AM
Show conn <IP source>
This give you if host try connect to specific IP.
Note:- you can specify tcp/udp port
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide