I've noticed something idiosyncratic with respect to the behavior of the IOS Embedded Packet Capture (EPC) feature in IOS 12.4(22T).
I have a DMVPN virtual tunnel interface (IPSEC encrypted). When I apply an outbound-only EPC capture point for cef-switched packets to the tunnel interface and view the capture, I see only what I would expect to (and do) see on the tunnel's parent interface: ESP packets with the source and destination addresses of the DMVPN headends - the packets which comprise the tunnel, i.e. the outside of the tunnel. Inbound I see the traffic within the tunnel, as expected.
If the capture point is set to collect outbound-only process-switched packets instead of cef, I seem to see BOTH the process-switched packets within the tunnel and the encapsulating ESP packets.
Is this behavior documented anywhere?
Is there any way to capture the outbound tunnel contents for cef-switched packets?