cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
876
Views
0
Helpful
5
Replies

FWSM and capture.

andrea.meconi
Level 2
Level 2

Another question about FWSM with software 4.1(1).

Using capture, we are able to view the captured packets after a minute, or more, that they hit the interface.

Why?

Regards.

Andrea

1 Accepted Solution

Accepted Solutions

Hi Andrea,

Yes, unfortunately all of the rules need to be recompiled whenever an ACL change is made. Therefore, this is expected behavior if you have a large set of ACLs.

-Mike

View solution in original post

5 Replies 5

mirober2
Cisco Employee
Cisco Employee

Hi Andrea,

Do you mean that it takes a minute or so before you see any packets show up in the capture you configured? If so, this is expected when you configure a new ACL to be used with a capture. The capture will not start showing packets until the ACL used to match the traffic is finished compiling.Therefore, the longer it takes for the ACLs to compile, the longer it will be before you start seeing any data in your capture.

Hope that helps.

-Mike

You are right Mike.
But this happens with an ACL with two entries also?

Regards.

Andrea

Hi Andrea,

Yes, unfortunately all of the rules need to be recompiled whenever an ACL change is made. Therefore, this is expected behavior if you have a large set of ACLs.

-Mike

Many thanks for your help Mike.

Regards.

Andrea

Sorry Mike. To be clear, FWSM captures all packets but shows these after some minutes, when session is already closed.

Review Cisco Networking for a $25 gift card