Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA capture files not being read by Wireshark

I took some capture files this morning on our ASA appliance. I actually view the packets being captured with the real time command. Once I had what I needed, I ended the capture. I then FTP the trace files to my workstation, opened Wireshark to then point to the files. I keep getting this message when I try to open the files::The file "C:\FTProot\lori_ip" isn't a capture file in a format Wireshark understands. I have tried using both a .pcap and a .cap extension. I am still getting the same error message.

Wireshark is opening other files just fine.

  • Firewalling
1 ACCEPTED SOLUTION

Accepted Solutions

Re: ASA capture files not being read by Wireshark

Hi Kevin,

Using the capture command, the syntax would look like this:

copy /pcap capture:[context/]

Here is a link to the command reference also:

http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/c4.html#wp2123161

Hope that helps.

-Mike

3 REPLIES
Cisco Employee

Re: ASA capture files not being read by Wireshark

When transferring the capture files, you must be sure to leverage the '/pcap' parameter to copy the file as a valid *.pcap file. You probably downloaded the file as the textual version. You may still be able to glean some information from the file if you open it within a text viewer.

You can also download the files leveraging the following URL:

https:///capture//pcap

Here's a helpful link for the packet capture feature:

http://www.nortfm.com/?View=entry&EntryID=1

New Member

Re: ASA capture files not being read by Wireshark

I am still having difficulty "leveraging" with the "/pcap" parameter. Where exactly in the copy command does it belong. I have tried it everywher and the ASA is just not liking it...

Re: ASA capture files not being read by Wireshark

Hi Kevin,

Using the capture command, the syntax would look like this:

copy /pcap capture:[context/]

Here is a link to the command reference also:

http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/c4.html#wp2123161

Hope that helps.

-Mike

2228
Views
0
Helpful
3
Replies