12-01-2010 12:59 AM - edited 03-11-2019 12:17 PM
Another question about FWSM with software 4.1(1).
Using capture, we are able to view the captured packets after a minute, or more, that they hit the interface.
Why?
Regards.
Andrea
Solved! Go to Solution.
12-01-2010 06:42 AM
Hi Andrea,
Yes, unfortunately all of the rules need to be recompiled whenever an ACL change is made. Therefore, this is expected behavior if you have a large set of ACLs.
-Mike
12-01-2010 06:29 AM
Hi Andrea,
Do you mean that it takes a minute or so before you see any packets show up in the capture you configured? If so, this is expected when you configure a new ACL to be used with a capture. The capture will not start showing packets until the ACL used to match the traffic is finished compiling.Therefore, the longer it takes for the ACLs to compile, the longer it will be before you start seeing any data in your capture.
Hope that helps.
-Mike
12-01-2010 06:36 AM
You are right Mike.
But this happens with an ACL with two entries also?
Regards.
Andrea
12-01-2010 06:42 AM
Hi Andrea,
Yes, unfortunately all of the rules need to be recompiled whenever an ACL change is made. Therefore, this is expected behavior if you have a large set of ACLs.
-Mike
12-01-2010 06:47 AM
Many thanks for your help Mike.
Regards.
Andrea
12-01-2010 06:56 AM
Sorry Mike. To be clear, FWSM captures all packets but shows these after some minutes, when session is already closed.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide