08-02-2022 01:34 AM
Hi teams,
As to my knowledge, there are two command about capturing packet in FTD.
First, 'capture' command like ASA command. Second, 'capture-traffic' command based on tcpdump I think.
These two command divided into where I capture starts like below picture.
So, I checked these two command in person at virtual environment(Decrypting SSL traffic by resign).
But, the output was same each other.
[1.LIna capture / using capture command]
[2.Snort capture / using capture-traffic command]
I think It may no ssl/tls process in lina capture file because it didn't pass the snort engine(DAQ or ssl decrpyt).
But I can see all ssl/tls process. So, I was confused.
Am I missing something?
Thank you.
08-02-2022 01:59 AM
make SNORT drop the traffic and see the different.
08-03-2022 01:42 AM
The commands provide the same information, the only difference is where the capture is taken so to help identify where packets might be dropped.
to see the SNORT process verdicts, you can use the command system support trace.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide