Wireshark-users: Re: [Wireshark-users] Cisco FWSM Capture Dump

From: "Robert D. Scott" <robert@xxxxxxx>
Date: Mon, 10 Aug 2009 10:55:39 -0400
dcpopl3-fwsm-1/cns/act# copy capture disk0: ?
ERROR: % Unrecognized command
dcpopl3-fwsm-1/cns/act# copy capture disk0:c1 ?
ERROR: % Unrecognized command
dcpopl3-fwsm-1/cns/act# copy capture disk0:c1
                                     ^
ERROR: % Invalid input detected at '^' marker.
dcpopl3-fwsm-1/cns/act# sho ver

FWSM Firewall Version 4.0(2) <context>

Compiled on Tue 29-Jul-08 15:50 by fwsmbld 

I only wish it worked like the ACE and ASA. :(

Robert D. Scott                 Robert@xxxxxxx
Senior Network Engineer         352-273-0113 Phone
CNS - Network Services          352-392-2061 CNS Phone Tree
University of Florida           352-392-9440 FAX
Florida Lambda Rail             352-294-3571 FLR NOC
Gainesville, FL  32611          321-663-0421 Cell


-----Original Message-----
From: wireshark-users-bounces@xxxxxxxxxxxxx
[mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of Joerg Mayer
Sent: Monday, August 10, 2009 10:24 AM
To: Community support list for Wireshark
Subject: Re: [Wireshark-users] Cisco FWSM Capture Dump

On Mon, Aug 10, 2009 at 08:06:43AM -0400, Robert D. Scott wrote:
> That is an ASA, and is based on the same hardware as the ACE.  This is an
> older FWSM.  Both the ACE and ASA will allow the export. This is a FWSM
> running 4.0, and there is nothing in the Cisco docs, or that I can find in
> the CLI to export.  Just the text dump I sent. :(

I looked at:
Catalyst 6500 Series and Cisco 7600
Series Switch Firewall Services Module
Command Reference, 4.0

and think that the "capture" command should be able to do what you want,
but I may be mistaken. Capture the packet, then "copy capture" it to some
remote URL.

Ciao
    Joerg
-- 
Joerg Mayer                                           <jmayer@xxxxxxxxx>
We are stuck with technology when what we really want is just stuff that
works. Some say that should read Microsoft instead of technology.
___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users@xxxxxxxxxxxxx>
Archives:    http://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
 
mailto:wireshark-users-request@xxxxxxxxxxxxx?subject=unsubscribe