Using the capture command in a Cisco Systems PIX firewall.
A vital tool to use when troubleshooting computer networking problems and monitoring computer networks is a packet sniffer. That being said, one of the best methods to use when troubleshooting connection problems or monitoring suspicious network activity in a Cisco Systems PIX firewall is by using the capture command. Many times Cisco TAC will request captures from a PIX in PCAP format for open problem tickets associated with unusual problems or activity associated with the PIX and the network.
The capture command was first introduced to the PIX OS in version 6.2 and has the ability to capture all data that passes through the PIX device. You can use access-lists to specify the type of traffic that you wish to capture, along with the source and destination addresses and ports. Multiple capture statements can be used to attach the capture command to multiple interfaces. You can even copy the raw header and hexadecimal data in PCAP format to a tftp server and open it with TCPDUMP or Ethereal.
- Add new comment
- 4171 reads

Recent comments
2 weeks 4 days ago
2 weeks 5 days ago
25 weeks 5 days ago
28 weeks 3 days ago
32 weeks 3 days ago
32 weeks 4 days ago
37 weeks 4 days ago
39 weeks 3 days ago
40 weeks 23 hours ago
40 weeks 3 days ago