04-29-2008 10:31 AM - edited 03-11-2019 05:38 AM
I am running FWSM Firewall Version 3.2(3). I am trying to copy the contents of my capture buffer so that I can look at it with Wireshark. The documentation states that you can use the pcap keyword for this. I cannot get the firewall to recognize said keyword. Documentation states this was introduced in 2.2(1). Has anyone done this? Thank you.
04-29-2008 01:42 PM
If the FWSM works like a PIX/ASA, this should work.
1. Create an ACL to capture the "interesting" traffic
ex. access-list cap1 extended permit ip host 1.1.1.1 host 2.2.2.2
2. Create a capture to use your ACL
ex. cap my_cap access-list cap1 interface outside
3. View the capture
ex. show cap my_cap
4. Download the cap (ASDM must be setup)
ex. https://
Jay
04-30-2008 06:38 AM
It does not seem to, but thank you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide