Packet capture and sniffing using the Cisco ASA Firewall



Sponsored Links


Starting with the new Cisco ASA firewall version 7.2(1), you can now capture detailed packet information traversing the firewall for analysis and for troubleshooting problems.

To enable packet tracing capabilities for packet sniffing and network fault isolation, use the packet-tracer command. To disable packet capture capabilities, use the no form of this command.

packet-tracer input [src_int] protocol src_addr src_port dest_addr dest_port [detailed] [xml]

no packet-tracer

In addition to capturing packets, it is possible to trace the lifespan of a packet through the security appliance to see if it is behaving as expected. The packet-tracer command lets you do the following:

  • Debug all packet drops in production network.
  • Verify the configuration is working as intended.
  • Show all rules applicable to a packet along with the CLI lines which caused the rule addition.
  • Show a time line of packet changes in a data path.
  • Inject tracer packets into the data path.

The packet-tracer command provides detailed information about the packets and how they are processed by the security appliance. In the instance that a command from the configuration did not cause the packet to drop, the packet-tracer command will provide information about the cause in an easily readable manner. For example if a packet was dropped because of an invalid header validation, a message is displayed that says, “packet dropped due to bad ip header (reason).”

Examples
To enable packet tracing from inside host 10.2.25.3 to external host 209.165.202.158 with detailed information, enter the following:

hostname# packet-tracer input inside tcp 10.2.25.3 www 209.165.202.158 aol detailed 

Bookmark and Share

Related posts:

  1. Firewall Technologies
  2. Prevent Spoofing Attacks on Cisco ASA using RPF
  3. IOS Packet Capture and Auto Upgrade
  4. ASA Firewall NAT Control Feature
  5. How to Configure a Cisco ASA 5510 Firewall – Basic Configuration Tutorial






3 Responses to 'Packet capture and sniffing using the Cisco ASA Firewall'

  1. packet tracer - May 14th, 2008 at 10:37 am

    [...] problems. To enable packet tracing capabilities for packet sniffing and network fault ihttp://www.cisco-tips.com/packet-capture-and-sniffing-using-the-cisco-asa-firewall/Packet Tracer 4.1 Full Version Download, Packet Tracer 4.1 Crack …Packet tracer 4.1 full download, [...]

  2. Daniel Craig - May 24th, 2009 at 7:59 am

    Hey, I was looking around for a while searching for Wireless Packet Sniffer and I happened upon this site and your post regarding capture and sniffing using the Cisco ASA Firewall | CiscoTips, I will definitely this to my Wireless Packet Sniffer bookmarks!

  3. Daniel Craig - July 30th, 2009 at 11:59 am

    Hello, I was looking around for a while searching for Wireless Video Sniffer and I happened upon this site and your post regarding capture and sniffing using the Cisco ASA Firewall | CiscoTips, I will definitely this to my Wireless Video Sniffer bookmarks!


Leave a Reply

cisco asa firewall ebook

Configuration Tutorial For Cisco ASA 5500 Firewalls
With FREE ASA 5505 Configuration Tutorial Bonus

CLICK HERE TO DOWNLOAD EBOOKS

Sponsored Links