fir3net
PPS-Firenetbanner-780.5x190-30-03-17

PIX - How to view packet captures within Wireshark

Below provides the nessecary steps required to create an a packet capture on an ASA/PIX, and the relevant download method.

Note :

  • You will requre pscp (putty pscp) installed onto your PC. Download pscp here.
  • This is only available in the later versions of PIX & ASA.

First of all start the capture.

capture capturefile type raw-data interface [interface name]

Next enable scp and copy the capture into Flash.

ssh scopy enable
copy /pcap capture:capturefile flash:capturefile.cap

On your PC run the following syntax via 'Start | Run | CMD' to download the capture to your PC.

pscp -scp [user]@][PIX IP]:capturefile.cap capturefile.cap 

Tags: PIX, Cisco, Firewall, Wireshark

About the Author

RDonato

R Donato

Ricky Donato is the Founder and Chief Editor of Fir3net.com. He currently works as a Principal Network Security Engineer and has a keen interest in automation and the cloud.

You can find Ricky on Twitter @f3lix001