03-20-2009 11:01 AM - edited 03-11-2019 08:08 AM
Hi Everybody,
I am trying to configure packet capture in ASA 5520 for troubleshooting. I am in the impression that
1. The captured data is stored in the RAM of the Firewall. Is this correct?
2. If that the case won't the firewall run out of memory for normal traffic if I run the capture of sometime?
3. How to reserve the memory space for packet capture?
Can anybody help me on this?
R.B.Kumar
Solved! Go to Solution.
03-20-2009 12:11 PM
Hi,
Check here
http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/c1.html#wp2108895
By default ASA only reserves 512k for capture and stops when it is filled, but you can increase this using the buffer option ie
capture CAP-NAME access-list CAP-ACL interface outside buffer 20000
Or you can use a circular buffer to keep capture running ie
capture CAP-NAME access-list CAP-ACL interface outside buffer 20000 circular-buffer
Regards
03-20-2009 12:11 PM
Hi,
Check here
http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/c1.html#wp2108895
By default ASA only reserves 512k for capture and stops when it is filled, but you can increase this using the buffer option ie
capture CAP-NAME access-list CAP-ACL interface outside buffer 20000
Or you can use a circular buffer to keep capture running ie
capture CAP-NAME access-list CAP-ACL interface outside buffer 20000 circular-buffer
Regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide