cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
567
Views
2
Helpful
6
Replies

How to capture dropped packet in ftd firewalll

Hello

could you please share the solution for showing dropped packet from internet to inside lan ? 
i have FTD 4100 series managed by fmc 

I want to see output from cli or fmc related to nat transactions packet(dropped and passed) both. 

 

6 Replies 6

If you do the capture from Lina engine by typing "system support diagnostic-cli" from the > line in the FTD, then you can set the capture as you would do it on the ASA adding the "asp-drop" keyword to the command similar to this:

capture CAP type asp-drop < select the ASP drop type >

Hello. 

below command is worked to capture dropped packed . 

> capture asp type asp-drop all match ip any host xx.xxx.xx.xx
>show capture asp

 

thank you for you support .

That works as well : - D.

Asp-drop all' 

This will not give anything.

This steps is last one in troubleshooting' 

First try packet-tracer 

If you see the result of packet tracer is drop for example route' the  you can use capture asp-drop type route.

Do packet-tracer as I mention above 

See in which phase the packet is drop

Share here if ypu want 

MHM

@MHM Cisco World, FYI, NAT is a function of Lina, so "capture type asp-drop" will do exactly what the user was ask ing about, i.e. show packets dropped by NAT. Of course, specific NAT-related drop codes can be specified in the command to narrow it down.

 

Review Cisco Networking for a $25 gift card