cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3390
Views
0
Helpful
1
Replies

FTD with asp-drop packet capture continues to run - can't stop

baskervi
Level 1
Level 1

We had a previos TAC case open when the engineer created an asp-drop packet capture. It wasn't deleted, and we're having a problem today, so I decided to crank that up to see what packets may be dropped. Packets are flying across the screen, and I can't stop it. I've been working with another TAC engineer for 30 minutes, and he can't stop it. Anyone have ideas? CTL-C, CTL-Z, etc don't work. Thanks

1 Reply 1

TJ-20933766
Spotlight
Spotlight

You could try to see what the name of the capture is by issuing the command:

FTD-1# show capture
capture MYCAP type raw-data buffer 1534 interface inside [Buffer Full - 1225 bytes]
match ip any any

As you type this, you will not likely be able to see that you are typing anything but you are. Just type the command and hit enter. The result will be on the screen for just a split second but you could disconnect your session right after hitting enter and scroll back in the buffer and find it. Once you have the name of the capture, reconnect to the FTD and issue the command no capture [capture-name]

FTD-1# no capture MYCAP

 

Review Cisco Networking for a $25 gift card