MicroNugget: How to Use ASA Firewall Packet Capture

preview_player
Показать описание

In this video, Keith Barker covers implementing packet captures on an ASA firewall. Watch to see — if you've got a user making requests to an external resource, and you want to collect a packet capture between them — how to make that capture.

Imagine you've got a user making regular trips out to the internet, and receiving replies back. If you've got an ASA sitting in the middle, it's probably doing stateful inspection of all that traffic, but maybe that's not enough. Maybe you're looking to gather a packet capture between that user and whatever resource is sending the replies.

Available options include setting up a protocol analyzer on the user's computer, but that's inefficient at scale and pretty invasive for that device, or setting up a SPAN port on the nearest switch, but again - invasive and inefficient. The quickest way would be to make use of that ASA that already sits between the traffic. Watch and see how to configure a protocol analyzer via the ASDM Wizard, and how to download captured information with a copy command right from the CLI.

Start learning with CBT Nuggets:

Рекомендации по теме
Комментарии
Автор

When I want to learn anything in Network subjects, I watch Keith BARKER's Videos...

frano
Автор

I love your videos Keith..Keep up the good work!

afbraganza
Автор

Your videos are really helpful, thanks alot..i have one query, can you show example from an specific host to a specific destination ? Also the use of ACL list on this packet capture wizard?

sonalivapilkar
Автор

Captures usually involve an interface.

jpborralho
Автор

That was really informative, how awesome was that rite !!  Thanks Sir Keith.. That was great !! Loved the security techs.Sir if i could make a request i would love to see videos for demonstrating the hacking tools available for white hat purposes. I'm a newbie so would love to take tips.

freddyfelix