11-04-2023 06:09 PM
HI all,
I have Catalyst 4500 L3 Switch and I am trying to capture some packets with EPC from outside my LAN but I see only packets coming from inside my network. I have configured my access list for EPC like this:
permit ip any host xx.xx.xx.x
permit ip host xx.xx.xx.x any
I want to see the packets for only one ip address. So when I ping ip address from my switch I see the packets coming. But when I try to ping it from outside my network nothing is coming. The IP address is definitely reachable from outside. I think the EPC is configured properly because I wouldn't see any packets at all. Does someone maybe know what might be the problem?
Solved! Go to Solution.
11-05-2023 05:04 AM
there are CEF and process switching,
remove the CEF from capture and check again (make the direction BOTH).
Thanks A Lot
MHM
11-05-2023 01:52 AM
Is the 4500 performing NAT on the traffic?
11-05-2023 04:41 AM
No, there is no NAT configured on the switch.
11-05-2023 02:42 AM
do you apply the packet capture control-plane IN or OUT direction ??
Thanks A Lot
MHM
11-05-2023 04:53 AM
I have set it to be both direction. Like this:
monitor capture point ip cef POINT vlan 45 both
I forgot to mention that it is a vlan interface but as I said the IP address is definitely reachable from outside so I don't know if it matters.
11-05-2023 05:04 AM
there are CEF and process switching,
remove the CEF from capture and check again (make the direction BOTH).
Thanks A Lot
MHM
11-05-2023 12:24 PM
I removed CEF and now I can see some packets from outside but they are not mine. When I ping and ssh to my host I still don't see that packets coming. Could a host somehow be blocking to see the packets? Thanks for help MHM, I am new to this and I am still learning.
11-05-2023 12:36 PM
Use from-us to check ping/ssh/telnet from SW or to SW.
11-06-2023 01:56 PM
Thank you for help
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide