cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2403
Views
20
Helpful
2
Replies

Firepower CLI: Capture vs. Capture-Traffic

cpaquet
Level 1
Level 1

Would someone help me understand the difference of: > capture     and > capture-traffic.  When would I use one over the other?  

The only differences I see are:

1. capture focuses on one interface

2. capture-traffic can be much more verbose, and has dozens of options to augment the granularity of information.

 

Anything else?  Am I missing something?

 

Thanks.

Cath.

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

The commands differentiate between a LINA (ASA subsystem) type capture at the ingress or egress interface vs a Snort capture which happens after the packets are passed to the Snort subsystem via the DAQ.

Firepower capture types.PNG

View solution in original post

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

The commands differentiate between a LINA (ASA subsystem) type capture at the ingress or egress interface vs a Snort capture which happens after the packets are passed to the Snort subsystem via the DAQ.

Firepower capture types.PNG

Wow.  Outstanding explanation Marvin.  Could you become the Writer-in-Chief of the Command Reference Guide for Firepower? ;)

Review Cisco Networking products for a $25 gift card