cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
845
Views
5
Helpful
2
Replies

What is difference 'capture' and 'capture-traffic' in Firepower?

HWAN
Level 1
Level 1

Hi teams,

As to my knowledge, there are two command about capturing packet in FTD.

First, 'capture' command like ASA command. Second, 'capture-traffic' command based on tcpdump I think.

These two command divided into where I capture starts like below picture.

1.png

So, I checked these two command in person at virtual environment(Decrypting SSL traffic by resign).

But, the output was same each other.

[1.LIna capture / using capture command]

2(lina).png

[2.Snort capture / using capture-traffic command]

3(snort).png

I think It may no ssl/tls process in lina capture file because it didn't pass the snort engine(DAQ or ssl decrpyt).

But I can see all ssl/tls process. So, I was confused.

Am I missing something?

Thank you.

 

2 Replies 2

make SNORT drop the traffic and see the different.

The commands provide the same information, the only difference is where the capture is taken so to help identify where packets might be dropped.

to see the SNORT process verdicts, you can use the command system support trace.

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card