What goes where ???

I've used cisco for some time now, and are realy happe with it, but there is one thing i need to get a hang of..
Traffic from one vlan going out to internet, and traffic comming back...
All i see is traffic comming from 1 ip out on internett going to my external ip on any given port.
Is there a way i can wee what inside ip address it's going against and what inside ip it's comming from ??
We have a asa5510 with aprox 8 vlan's on the inside and it would be nice to see what user is causing the internet traffic and why there are so many hit's on the firewall  :-)
Thnks for any help
Thomas
pst not to good on command, mainly used gui :-)                  

Hi,
A basic packet capture configuration for ASA could look something like this
access-list TRAFFIC-CAPTURE permit ip 10.10.10.0 255.255.255.0 any
access-list TRAFFIC-CAPTURE permit ip any 10.10.10.0 255.255.255.0
capture TRAFFIC-CAPTURE type raw-data access-list TRAFFIC-CAPTURE interface inside buffer 33500000 circular-buffer
Where
TRAFFIC-CAPTURE = Is the ACL that defines the traffic to be captured. The above ACL captures both directions of the traffic when the source is 10.10.10.0/24 and destination is "any" (and vice versa naturally)
10.10.10.0/24 = Is an example LAN network located behind "inside" interface (or is the interface network)
inside = Is the interface from which the capture is taken from
33500000 = Is pretty close to the max buffer memory you can have on any ASA firewall for a single capture You can make separate capture for each direction and later attach the capture files using wireshark
circular-buffer = Is the setting that will permit the ASA to overwrite the old captured data when the buffer is full. Capture will keep on working but old data will be overwritten as new data is being captured.
Naturally the above ACL is VERY broad. You can change the capture to only capture one "host" traffic. Or only capture TCP or UDP traffic only. You can limit to some certain destination IP addresses. Just control as you like with the ACL.
To show if traffic is hitting the capture
show capture
To show a specific capture and its contents
show capture
To copy a capture to external TFTP server
     To be later opened with Wireshark for example
copy /pcap capture: tftp://x.x.x.x/.pcap
To remove a capture from ASA
Also removes the collected data
no capture
Hopefully the above information has been helpfull. Please do rate if it has been and naturally ask more if needed.
- Jouni

Similar Messages

  • What goes where when using separate drives for data and applications?

    Hello people!
    In Mac Guru's "Guide to Macintosh Performance Acceleration" it states " Separating your "User" data from the Operating System and Applications is the simplest and most cost effective way to enjoy a significant performance boost at
    minimal cost"...
    Now how exactly do I do that?
    I have a 40 GB HD with Panther on it and a 55 GB drive I want to use for the "data" drive. What goes where?
    Thanks for reading!

    Hello Danny:
    Welcome to Apple discussions.
    I disagree with the premise in that article - "significant" is relative and depends on where you are. The only method I am aware of to "separate" would be to create partitions. OS X uses sophisticated algorithms to manage memory - both real and virtual. There are very few good reasons to partition an internal HD - and several that suggest you should not do that - absent a "good" reason.
    Barry

  • Another "What goes where" thread

    Hi guys
    I am a little unsure how to configure "what goes where" on my main rig.
    I have these discs:
    Corsair 256 GB Pro (holds atm system, program files and pagefile)
    Single 1.5 TB WD black (all kinds of stuff other than video)
    Raid 0 on LSI 4 chnl. ctr. - 2 x Caviar 600 GB (holds now project files and maedia for PPRO)
    Raid 0 on LSI 4 chnl. ctr. - 2 x Caviar 1 TB (holds render now)
    SSD 240 GB for mediacache and preview for both AE and PPRO CS6
    Should I add another single disc for project files alone and/or move the pagefile?
    Thanks
    Ulf

    Jim, I completely agree considering your own system, but not on Ulf's system, which is way faster than yours.
    Ulf,
    If you want to add another two disks, I suggest:
    C: 256 GB OS & programs & pagefile, SATA 6G
    D: 240 GB Windows temp & media cache & AE cache, SATA 6 G
    E:  2 x 600 WD in raid0 on the Marvell controller, previews. SATA 6G
    F: 4 x 1 TB in raid5 on the LSI for media and projects
    G: 1.5 TB exports and backup.
    FYI, yesterday Bill gave me some experimental figures on the new test we are working on. Exporting a two hour timeline on an i7-2600K with a single OCZ Vertex4 SSD was around 6 times slower compared to a system with a heavy raid array. 84 seconds versus 14 seconds. Jim's suggestion to break out the raids you currently have will only slow down your system. In Jim's case he will not notice it, because his system is so much slower than yours, but you definitely will notice it.
    The complicating factor in your case is the variety of disks you have and only a 4 port controller. The E: drive is way too big for previews only, but you don't have many choices for alternative uses and despite that they are older drives, in a raid0 they do give you nice performance. Going from 2 x 1 TB raid0 to 4 x 1 TB raid5 on that controller will give you added performance plus security against disk failure. Don't expect miracles in performance boost from 2x R0 to 4x R5, it will probably be only 25-35% or around that figure.

  • Domain name, host name - what goes where?

    So to clear the pipeline and reduce the amount of configuration, I decided to get rid of my router and plug my server directly into the modem, thus using the server as the gateway/router for other computers in my home. Hopefully this will eliminate the need for an internal/private network DNS configuration as well as an external/public DNS configuration.
    I have a registered public domain name of N.com and an associated public MX record for this domain which is also named N.com (as opposed to mail.N.com or something similar).
    I reinstalled the Leopard Server software and when the setup asked for a "primary DNS name" I named it N.com (the same name as my registered public domain). I went into firewall settings in the Server Admin and "allowed"/opened port 25 as well as 80 for email and web services respectively.
    When I looked in the Mail settings the default domain name is "localdomain" and the default hostname is N.com (the same as my registered public domain). Default user addresses are [email protected] I have no problem seeing the server's webpages from the internet, but I still cannot get any mail from the internet to show up in my user accounts.
    What more do I need to do?

    an educated guess-
    does the client's email system have something like Spam
    Assassin filtering
    incoming mail?
    is this cgi script matt wright's formmail?
    If yes to both- Spam Assassin is rating the formmail
    generated email as spam
    based on the subject line and default first line of text in
    the message
    body.
    A fix-
    1) hand edit the formmail script, find and change:
    Below is the result of your feedback form
    to any other text
    2) use the optional field to change the subject line from the
    default.

  • What Goes Where andhow to email!

    Hello
    Looking for a little help here, this is the first time i
    would have written AS im more a PHP man but have used flash alot to
    create more movie type interatcive sites anyway im using FLASH CS3
    I have 4 Text Inputs and a Button with instances
    name_box
    email_box
    tele_box
    Message_box
    send_btn
    There on a Graphics Symbol thats inside a Movie Symbol thats
    placed in the main screen on frame 169
    on frame 172 is animation that i would like to show while the
    data is being sent frame 173 is an error and 174 is the confirm
    The PHP file im trying to post these to is working fine (with
    other HTML websites)
    Now this is what i have got in the action script inside a
    layer on the graphic symbol that holds the fields:
    stop();
    System.useCodepage = true;
    send_btn.onRelease = function() {
    my_vars = new LoadVars();
    my_vars.name = name_box.text;
    my_vars.email = email_box.text;
    my_vars.tele = tele_box.text;
    my_vars.message = message_box.text;
    if (my_vars.name != "" and my_vars.email
    != "" and my_vars.message !=
    "") {
    my_vars.sendAndLoad("mailer.php", my_vars,
    "POST");
    gotoAndStop(172);
    } else {
    gotoAndPlay(173);
    my_vars.onLoad = function() {
    gotoAndStop(174);
    After this not working it tried placing
    gotoAndPlay.root(frame number) but this didn't work and tried
    placing the original action script on the main in a layer of its
    own
    Anyone have any ideas to how i could get the to work?
    Thank you in advanced

    AS should only go in the main timeline.
    >>my_vars.sendAndLoad("mailer.php", my_vars, "POST");
    You should probably be using a full URL here:
    my_vars.sendAndLoad("
    http://www.mydomain.com/scripts/mailer.php",
    my_vars,
    "POST");
    Dave -
    Head Developer
    http://www.blurredistinction.com
    Adobe Community Expert
    http://www.adobe.com/communities/experts/

  • I have 2 phones on a single apple ID, and am getting email and texts to both phones... can i configue what goes where from the cloud?

    My son shouldnt have his own Apple ID yet, and I dont want him getting my email and texts. Anyone know how to configure the cloud to stop this?

    Well yes, but if you want to update those apps, you'd need to sign in under your old Apple ID to update them. It's really best to just stick to one Apple ID, or you'll run into association complications down the road.

  • What tier goes where

    Hi,
    with a web (jsp) application, the tier architecture is simple:
    Database tier -> middle tier (webserver) -> client tier (webbrowser)
    But what about JClient apps.
    Database tier -> middle tier (bc4j) -> client tier (jclient) ?
    Where does code execute. If I use a viewobject to populate a JTree, does it 'run' on the middle tier (application server), or does it run on the client machine in the jclient application? What and where's exactly the separation between gui and middle tier?
    In a web environment, the browser is the 'thin' client, which knows only html. All business logic is performed on the server. Is the JClient situation comparable? Or is a jclient a much less thin client?

    As you're familiar, BC4J allows you to build J2EE-compliant apps with a clean, logical three-tier design. You can then choose to deploy your application as a physical two tier application, or a physical three-tier application as your needs require. These rules hold, regardless of the client implementation technology.
    Two concrete examples of a physical two-tier physical deployment are:
    [list=1]
    [*]JClient application talking to BC4J appmodule in local mode
    [*]JSP pages using BC4J datatags talking to BC4J appmodule in local mode
    [list]
    Two concrete examples of a physical three-tier deployment are:
    [list=1]
    [*]JClient application talking to BC4J appmodule deployed as an EJB Session Bean in a J2EE Container on another machine
    [*]JSP pages using BC4J datatags talking to BC4J appmodule deployed as an EJB Session Bean in a J2EE Container on another machine
    [list]
    Of course, the degenerate case of the last example above occurs when the JSP pages and the EJB Session Bean actually reside on the same J2EE container, then you can use the EJB Session Bean option of BC4J with local interfaces.
    Regardless of the UI layer you're using, your client works with the set of BC4J interfaces in the oracle.jbo.* package.
    What changes in the two deployment scenarios is the classes in the JBO framework that implement these common interfaces.
    [list]
    [*]In a physical two-tier deployment (also known as "local mode"), the interfaces are implemented by classes in the oracle.jbo.server.* package.
    [*]In a physical three-tier deployment, the interfaces are implemented by classes in the oracle.jbo.client.* package (and its oracle.jbo.client.remote.* "sub"-package.
    [list]
    This is transparent to your application code since you are working with the interfaces.
    When you use the remote mode, the bulk of the implementation stays on the EJB tier inside your session bean. What travels to the client are collections of value objects which are managed by a client-side value-object cache that BC4J implements for you (but which you do not need to manage yourself). If you are, say, browsing the results of a query that has scrolled through 1000 records, BC4J will keep a "window" of rows of value objects on the client for you, where the size of the window is set via the setRangeSize() method on the view object you're working with.
    BC4J is also designed to keep its client-side value object cache kept in sync with any changes that occur in the business objects in the middle tier. For example, say you have some business logic coded into your Employee business object that increases an employee's salary by $1000.00 when their job category goes up a level. And let's say your client is working with a view of the data that shows:
    Empno    Ename    Salary     JobClass
    1234     Ivo      4321         4If the client updates the value of "JobClass" from 4 to 5, the attribute change on the client-side value object eventually makes it to the middle tier -- immediately if you are using the SYNC_IMMEDIATE mode, and on the next row navigation, row validation, or custom method invocation in the case of our SYNC_LAZY mode. In the middle tier, BC4J syncs the change in the client-side value object "row" of this view object query result and sets the "JobClass" view row attribute in the middle tier. Since view objects cooperate with entity objects, the setting of the "JobClass" on the view object row internally delegates to an attempt to set the "JobClass" attribute on the underlying entity object instance representing employee #1234 (which was created in the EO cache as this row was queried in from the database). Your business logic in the setJobClass() method at the Employee entity level contains the logic that decides that, based on the increase in job class, the salary should get incremented by $1000, so it calls setSalary() like this:
      private static final Number ONE_THOUSAND = new Number(1000);
      public void setJobClass(Number value) {
        setAttributeInternal(JOBCLASS, value);
        // If new job class is greater than old job class, increase salary by $1000
        Number prevJobClass = (Number)getPostedAttribute(JOBCLASS);
        if (value.compareTo(prevJobClass) > 0) {
          setSalary(getSalary().add(ONE_THOUSAND));
      }Part of the functionality of BC4J's unique "Value Messenger" design pattern implementation is that the framework keeps track of the "side-effects" of any middle-tier activity and automatically returns any relevant changes to the client-side value object cache to keep it in sync in the same round-trip that caused the activity to occur. In this example, the client is looking at a value object with the "Salary" attribute for employee #1234 and this employee's Salary has changed as a result of having set the JobClass attribute.
    The net effect is that the user types in a new job class of 5 and tabs to a new field, and the updated salary of 5321 appears automatically.
    Empno    Ename    Salary     JobClass
    1234     Ivo      5321         5  <---------This attribute changed by the user
                         \_______<_______ The updated salary (increased by $1000) appearsThis works both in local mode or 3-tier mode for JClient, JSP, or any of our supported "View-Layer" technologies that bind to the standard BC4J client interfaces in oracle.jbo.*
    So, in short, a BC4J JClient app that's deployed as a 3-tier application is a thin client with a small cache of value objects for view objects with active iterators open on the client.
    Let me know if you have more questions on this subject.

  • MacBook Pro (Retina, 15-inch, Mid 2014) will not read an SD card in the SDXC card reader. Does anyone know whats going on?

    MacBook Pro (Retina, 15-inch, Mid 2014) will not read an SD card in the SDXC card reader. Does anyone know whats going on?

    Hi David.  I don't have as modern a Macbook Pro as you, mine is a 2012 model, but perhaps I can help.  I often find that my SD card will not load when I first insert it.  I have to remove it and then put it into the slot again firmly.
    You also haven't posted any information about the SD card.  What size is it, do you know how it is formatted, has it worked in that same mac previously, where did it come from, does it currently work in another device (such as your camera)?  This sort of information will help to narrow down the problem.
    If you post some more information I'm sure people will try to help you.  In the meantime, if you look at your post again you should see "More Like This" at the bottom of the page and you may find an answer in some of those related posts.
    Hope that helps.
    Ivan

  • Just installed Mac OS X 10.8.5  on a Mac Pro 2010 platform.    The App Store shows there is an upgrade, so I click the download button.   After about 2 hrs the process stops and an  Error (102) appears on the screen.  Any idea what goes wrong?  THX

    Just installed Mac OS X 10.8.5  on a Mac Pro 2010 platform. 
    The App Store shows there is an upgrade, so I click the download button. 
    After about 2 hrs the process stops and an  Error (102) appears on the screen. 
    Any idea what goes wrong? 
    THX

    ahstephen wrote:
    Thank you for the response.
    The upgrade I'm interested is for OS X  v.10.8.5...
    ...The App Store page shows 2 different upgrades:   
    Mountain Lion  (10.8.5)  Software Upgrade,  and
    Yosemite FREE upgrade
    If the App Store is showing 10.8.5 as an update, what do you currently have installed? The final update to Mountain Lion was 10.8.5, and since the basic OS installation of Mountain Lion is no longer offered in the App Store, that would suggest you're currently at an earlier version of Mountain Lion - 10.8.x where x=less than 5. If that's the case, I'd suggest getting the 10.8.5 update. There is also a Supplemental Update for 10.8.5 and that may be what the App Store is offering.

  • Control what goes to cloud

    where can I control what goes to the cloud versus Apple "assisting" me?

    You can set data types in System Preferences>Cloud - Mail, Contacts, Calendars, Documents, Safari Bookmarks, Notes, Photo Stream. With Documents (you can choose which documents to save to iCloud though the deafult will be Cloud). With Calendars and Contacts you can save 'On My Mac' (which won't sync) or to Cloud. Otherwise it's all or nothing within a data type.

  • WhaTS going on with my hyper editor

    OK, so all of a sudden, when I create a GM set in my hyper editor the tags are wrong, for example where it says Kick 1 the sample I get is like a bongo or something, I've used the hyper edit with this instrument (the Garage band Rock Kit) like a hundred times and this has never happed before, whats going on?

    Welcome to the Apple Support Communities
    They replaced the logic board but not the memory. Take the Mac to an Apple Store to replace your memory or buy the memory and install it yourself

  • OK whats going on?

    Ok I have been waiting for Fibre to be installed to my local Exchange for a few years, the middle of last year we finally got a date on the 'Where and When' BT site that Fibre would be installed to our local Exchange in September 2014, I checked every day all of September then around mid October the site update to say it would be March 2015. I have checked the last few days and now we dont have a date anymore, its says this.
    We're keen to bring Superfast Fibre to your area and are exploring how best to achieve that. We may deliver it as part of our commercial programme, or by working in partnership with your local authority.
    So whats going on this was supposed to be part of the East Yorkshire rural broadband rollout, anyone got any ideas?
    Solved!
    Go to Solution.

    If you use this checker it will tell what cabinet you are on and what services it can receive.
    http://www.dslchecker.bt.com/adsl/adslchecker.welcome
    If it does not show a cabinet number it will be because you are on an Exchange Only(EO) line. This means you can not get Infinity because you are not connected to a cabinet, instead you are connected directly to the exchange.
    Sometime in the future Openreach may install a cabinet out side the exchange and this will allow EO lines to connect to a cabinet. This however is not high on their priority list so may take some time.
    Use your phone number. If you don't have a BT number use the address checker. It is more accurate than the post code checker which can cover more than one cabinet.

  • Somebody must know whats going on with PAL 720p HVX support !

    Ok this is getting really really anoying !
    Why has apple not mentioned anything about supporting PAL 720p in FCP ?
    Just a simple where on the case would be nice but no, nothing.
    I hate this kind of attitude and it severly hurts my investment in this camera and format.
    Why was it so easy to provide ntsc support but us pal owners are left feeling ignored.
    Just freeking tell us whats going on ............. aaaaaaaarghhh
    -matt
    G5 Dual 2.3 Power Mac 4 GiG RAM   Mac OS X (10.4.5)  

    720p25 is no officially supported format in general.
    Only 720p50 is a real standard. However there is a
    so called 2:2 pulldown where you double the frames,
    also called 25p over 50p. This only concerns a
    transparent video signal via HD-SDI. Speaking about
    the Panasonic HVX200 is another story as this is a
    file based workflow.
    Here you can find an article how to capture, edit and
    monitor 720p50 in FCP 5.1:
    http://www.aulich-adamski.de/en/perm/720p50-capturing-editing-in-final-cut-pro
    This is also helpful for JVC GY-HD users that could use
    an HDV to HD-SDI converter.
    An second article describes the Panasonic P2 workflow
    with 720p25 and 72p50 but it's currently only in german:
    http://www.aulich-adamski.de/perm/panasonic-ag-hvx200-720p2550-p2-workflow-mit-f inal-cut-pro

  • A movie I bought a while ago will no longer play, instead it just shows a black screen and no audio. All of the other movies in my library play fine. Any ideas as to whats going on or how to fix it? Thanks for any help.

    A movie I bought a while ago will no longer play, instead it just shows a black screen and no audio. All of the other movies in my library play fine. Any ideas as to whats going on or how to fix it? Thanks for any help.

    Hi 22chill,
    I recommend that we delete and re-download the movie from your purchase history:
    Downloading past purchases from the App Store, iBookstore, and iTunes Store
    http://support.apple.com/kb/HT2519
    Thanks,
    Matt M.

  • I am trying to use logic pro 9 on my lion system and it continues to say I have a bad midi...when i go to check my midi drivers folders in my library its empty...does anyone know whats going on?

    i am trying to use logic pro 9 on my lion system and it continues to say I have a bad midi...when i go to check my midi drivers folders in my library its empty...does anyone know whats going on?

    I
    got your message about making sure to use the machine specific disk that came with my machine. Unfortunately, Apple no longer sells Tiger replacement disks. I've got a couple of bids out on ebay, and will update when I have news to add to this post.
    Thank you for your help, Frank!
    To be clear you called the 800 number and explained what the situation was, old machine and lost the original DVD's?
    Just checking because if you just called and tried to buy the DVD's they might tell you they no longer sell them but you aren't really trying to buy them your trying to replace the ones that are missing.
    Ebay may work but there is a certain specificity to the DVD's required which, even if they seem right, might not work.
    Good luck either way. If you get a chance when you get the DVD's I'd be interested in hearing how it all works out.
    regards

Maybe you are looking for

  • Mail attachments - office for example word- cannot be opened

    In my mail account (GoogleMail) in iPad Mail, I cannot open the attachments (office word) and see the content. The only thing I see is the icon "W" in blue and the name of the attachment ".doc" I cannot mark or open it. No conten menue appears. I hav

  • Capital One back to back approvals $20,000

    Just checked my pre-qual offers on the cap1 website and Quicksilver and Venture appeared as pre-qualifications. I currently have a Quicksilver One MC ($2,000 CL) from 2013, a Platinum One MC ($2,500) from 2013, Venture Sig/$59 AF ($5,000 CL) from Nov

  • MOVED: REQUEST GOP / UEFI BIOS for MSI R9 270 GAMING

    This topic has been moved to GAMING Graphics Cards. https://forum-en.msi.com/index.php?topic=251368.0

  • Interactive, rotating globe - button problems

    I made an interactive rotating globe that shows all the continents (using CS3 and AS3). The globe rotates automatically. When the user mouses over the globe is stops rotating and they can use left/right arrows to rotate it manually to get to a contin

  • Startup Error:  scheduler: runtime exception during start up: null

    Dear All, We are getting the error in the scheduler service. Startup Error:  scheduler: runtime exception during start up: null We have installed TREX 7 on our Portal server (SP15). We can now create index but while assigning  datasource we are getti