cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1342
Views
0
Helpful
2
Replies

Need alternative to packet-tracer for Firepower 4110 with L7 rules on FMC

ABaker94985
Spotlight
Spotlight

Packet-tracer doesn't work reliably when you have upper layer rules on an FMC. Rules often show traffic is passed, when the FMC will actually block it. I know there is a similar method, and I heard that Cisco will eventually fix packet-tracer to work with the higher layer rules. Can someone send over directions? I've not been able to find this in the Firepower documentation. Thanks

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

It's not exactly the same, but if you have live traffic to check with you can get more reliable output using system support firewall-engine-debug and system-support-trace output.

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/214577-firepower-data-path-troubleshooting-phas.html

View solution in original post

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

It's not exactly the same, but if you have live traffic to check with you can get more reliable output using system support firewall-engine-debug and system-support-trace output.

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/214577-firepower-data-path-troubleshooting-phas.html

ABaker94985
Spotlight
Spotlight

That's exactly what I was looking for. Thank you!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card