2. Firepower Threat Defense 6 2: Advanced Troubleshooting (Packet Capture)

Опубликовано: 01 Октябрь 2024
на канале: Jason Maynard
4,301
9

The packet capture feature with trace option allows real packets that are captured on the ingress interface to be traced through the system. The trace information is displayed at a later stage. These packets are not dropped on the egress interface, as they are real data-path traffic. Packet capture for threat defense devices supports troubleshooting and analysis of data packets.

Once the packet is acquired, snort detects the tracing flag that is enabled in the packet. Snort writes tracer elements, through which the packet traverses. Snort verdict as a result of capturing packets can be one of DROP/ALLOW/Would DROP.

http://www.cisco.com/c/en/us/td/docs/...