<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to configure a packet capture in the Cisco ASA</title>
	<atom:link href="http://analysisandreview.com/cisco/how-to-configure-a-packet-capture-in-the-cisco-asa/feed/" rel="self" type="application/rss+xml" />
	<link>http://analysisandreview.com/cisco/how-to-configure-a-packet-capture-in-the-cisco-asa/</link>
	<description>Brain Dumps For All</description>
	<lastBuildDate>Wed, 29 Feb 2012 20:11:58 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Kurt</title>
		<link>http://analysisandreview.com/cisco/how-to-configure-a-packet-capture-in-the-cisco-asa/#comment-1574</link>
		<dc:creator>Kurt</dc:creator>
		<pubDate>Fri, 10 Feb 2012 03:56:26 +0000</pubDate>
		<guid isPermaLink="false">http://analysisandreview.com/uncategorized/how-to-configure-a-packet-capture-in-the-cisco-asa/9#comment-1574</guid>
		<description>send me the packet capture to kturner at absolutenetworks dot biz and I&#039;ll see what I can do for you =)

Lots of R&#039;s could mean a couple things so I&#039;d need to see the pcap</description>
		<content:encoded><![CDATA[<p>send me the packet capture to kturner at absolutenetworks dot biz and I&#8217;ll see what I can do for you =)</p>
<p>Lots of R&#8217;s could mean a couple things so I&#8217;d need to see the pcap</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mau</title>
		<link>http://analysisandreview.com/cisco/how-to-configure-a-packet-capture-in-the-cisco-asa/#comment-1572</link>
		<dc:creator>Mau</dc:creator>
		<pubDate>Fri, 10 Feb 2012 03:11:48 +0000</pubDate>
		<guid isPermaLink="false">http://analysisandreview.com/uncategorized/how-to-configure-a-packet-capture-in-the-cisco-asa/9#comment-1572</guid>
		<description>I have trouble sometimes analysing the results of this packet capture, especially the meaing of these different flags. S, P, R. I cant find document on this. anyone who has document or links on these flags and analysis in ASA packet capture? 
I have citrix issue which can&#039;t authenticate from external, and I did capture. but most of the flags is &quot;R&quot;, i know it reset, but why the host is resetting? thanks in advance for any input.</description>
		<content:encoded><![CDATA[<p>I have trouble sometimes analysing the results of this packet capture, especially the meaing of these different flags. S, P, R. I cant find document on this. anyone who has document or links on these flags and analysis in ASA packet capture?<br />
I have citrix issue which can&#8217;t authenticate from external, and I did capture. but most of the flags is &#8220;R&#8221;, i know it reset, but why the host is resetting? thanks in advance for any input.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kurt</title>
		<link>http://analysisandreview.com/cisco/how-to-configure-a-packet-capture-in-the-cisco-asa/#comment-1500</link>
		<dc:creator>Kurt</dc:creator>
		<pubDate>Wed, 01 Feb 2012 13:47:36 +0000</pubDate>
		<guid isPermaLink="false">http://analysisandreview.com/uncategorized/how-to-configure-a-packet-capture-in-the-cisco-asa/9#comment-1500</guid>
		<description>I&#039;ll have to try that today!! thanks =)</description>
		<content:encoded><![CDATA[<p>I&#8217;ll have to try that today!! thanks =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rajesh</title>
		<link>http://analysisandreview.com/cisco/how-to-configure-a-packet-capture-in-the-cisco-asa/#comment-1498</link>
		<dc:creator>rajesh</dc:creator>
		<pubDate>Wed, 01 Feb 2012 09:16:00 +0000</pubDate>
		<guid isPermaLink="false">http://analysisandreview.com/uncategorized/how-to-configure-a-packet-capture-in-the-cisco-asa/9#comment-1498</guid>
		<description>there is a command through which you can import captured packerts on your system from CLI console...

copy /pcap capture: tftp:


I hope this would be helpful for you all.</description>
		<content:encoded><![CDATA[<p>there is a command through which you can import captured packerts on your system from CLI console&#8230;</p>
<p>copy /pcap capture: tftp:</p>
<p>I hope this would be helpful for you all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kurt Turner</title>
		<link>http://analysisandreview.com/cisco/how-to-configure-a-packet-capture-in-the-cisco-asa/#comment-1362</link>
		<dc:creator>Kurt Turner</dc:creator>
		<pubDate>Thu, 13 Oct 2011 00:57:10 +0000</pubDate>
		<guid isPermaLink="false">http://analysisandreview.com/uncategorized/how-to-configure-a-packet-capture-in-the-cisco-asa/9#comment-1362</guid>
		<description>reset mean the connect is being closed and the two devices are communicating properly and the information e / communication exchange is completed</description>
		<content:encoded><![CDATA[<p>reset mean the connect is being closed and the two devices are communicating properly and the information e / communication exchange is completed</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anil</title>
		<link>http://analysisandreview.com/cisco/how-to-configure-a-packet-capture-in-the-cisco-asa/#comment-1361</link>
		<dc:creator>Anil</dc:creator>
		<pubDate>Thu, 13 Oct 2011 00:46:52 +0000</pubDate>
		<guid isPermaLink="false">http://analysisandreview.com/uncategorized/how-to-configure-a-packet-capture-in-the-cisco-asa/9#comment-1361</guid>
		<description>If i captured the data i want to meaning of each reply.
e.g. S – SYN
A- ACK R
R- reset etc.
If reset come from src then what meaning and come from dest then what is that mean.

Can any one of share this in details.</description>
		<content:encoded><![CDATA[<p>If i captured the data i want to meaning of each reply.<br />
e.g. S – SYN<br />
A- ACK R<br />
R- reset etc.<br />
If reset come from src then what meaning and come from dest then what is that mean.</p>
<p>Can any one of share this in details.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anil</title>
		<link>http://analysisandreview.com/cisco/how-to-configure-a-packet-capture-in-the-cisco-asa/#comment-1360</link>
		<dc:creator>Anil</dc:creator>
		<pubDate>Thu, 13 Oct 2011 00:46:23 +0000</pubDate>
		<guid isPermaLink="false">http://analysisandreview.com/uncategorized/how-to-configure-a-packet-capture-in-the-cisco-asa/9#comment-1360</guid>
		<description>If i captured the data i want to meaning of each reply.
e.g. S - SYN
A- ACK R
R- reset etc.
If reset come from src then what meaning and come from dest then what is that mean.

Can any one of share this in details.</description>
		<content:encoded><![CDATA[<p>If i captured the data i want to meaning of each reply.<br />
e.g. S &#8211; SYN<br />
A- ACK R<br />
R- reset etc.<br />
If reset come from src then what meaning and come from dest then what is that mean.</p>
<p>Can any one of share this in details.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kurt Turner</title>
		<link>http://analysisandreview.com/cisco/how-to-configure-a-packet-capture-in-the-cisco-asa/#comment-1175</link>
		<dc:creator>Kurt Turner</dc:creator>
		<pubDate>Mon, 18 Apr 2011 12:58:45 +0000</pubDate>
		<guid isPermaLink="false">http://analysisandreview.com/uncategorized/how-to-configure-a-packet-capture-in-the-cisco-asa/9#comment-1175</guid>
		<description>@jaykay

thanks jaykay - here are the commands to set up a port monitor the old school way.. just like we do in our switches.. 

hostname(config)# interface ethernet 0/1
hostname(config-if)# switchport monitor ethernet 0/0
hostname(config-if)# switchport monitor ethernet 0/2

So with this you&#039;ll plug your laptop oo PC in port ethernet 0/1 - all traffic from 0/0 and 0/2 will be pushed to 0/1 - set up wireshark to monitor traffic and there ya go</description>
		<content:encoded><![CDATA[<p>@jaykay</p>
<p>thanks jaykay &#8211; here are the commands to set up a port monitor the old school way.. just like we do in our switches.. </p>
<p>hostname(config)# interface ethernet 0/1<br />
hostname(config-if)# switchport monitor ethernet 0/0<br />
hostname(config-if)# switchport monitor ethernet 0/2</p>
<p>So with this you&#8217;ll plug your laptop oo PC in port ethernet 0/1 &#8211; all traffic from 0/0 and 0/2 will be pushed to 0/1 &#8211; set up wireshark to monitor traffic and there ya go</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jaykay</title>
		<link>http://analysisandreview.com/cisco/how-to-configure-a-packet-capture-in-the-cisco-asa/#comment-1163</link>
		<dc:creator>jaykay</dc:creator>
		<pubDate>Sat, 16 Apr 2011 21:50:27 +0000</pubDate>
		<guid isPermaLink="false">http://analysisandreview.com/uncategorized/how-to-configure-a-packet-capture-in-the-cisco-asa/9#comment-1163</guid>
		<description>Hi guys,

sure you can set up port mirroring on the ASA, see here:

http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s8.html#wp1411559

Best,

jaykay</description>
		<content:encoded><![CDATA[<p>Hi guys,</p>
<p>sure you can set up port mirroring on the ASA, see here:</p>
<p><a href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s8.html#wp1411559" rel="nofollow">http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s8.html#wp1411559</a></p>
<p>Best,</p>
<p>jaykay</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kurt Turner</title>
		<link>http://analysisandreview.com/cisco/how-to-configure-a-packet-capture-in-the-cisco-asa/#comment-650</link>
		<dc:creator>Kurt Turner</dc:creator>
		<pubDate>Tue, 22 Mar 2011 21:01:01 +0000</pubDate>
		<guid isPermaLink="false">http://analysisandreview.com/uncategorized/how-to-configure-a-packet-capture-in-the-cisco-asa/9#comment-650</guid>
		<description>the ACL will not stop traffic however if you have a large amount of production traffic it&#039;s going to have some performance impact.. I would try to limit it to IP addresses 

I&#039;ve never set up a port monitor or span on ASA.. not sure if you can.. just do the capture like I said and then open it up in a web browser to download the pcap - then you can open the pcap in your sniffer</description>
		<content:encoded><![CDATA[<p>the ACL will not stop traffic however if you have a large amount of production traffic it&#8217;s going to have some performance impact.. I would try to limit it to IP addresses </p>
<p>I&#8217;ve never set up a port monitor or span on ASA.. not sure if you can.. just do the capture like I said and then open it up in a web browser to download the pcap &#8211; then you can open the pcap in your sniffer</p>
]]></content:encoded>
	</item>
</channel>
</rss>

