Cisco – Packet capture on a Cisco ASA

ciscocisco-asa

how is packet capturing on the ASA firewall different or similar to setting up a syslog server for the capture.

I want to capture interesting traffic on the FW and store them for analysis during troubleshooting, currently the buffer size allows me to log only 3 hours of capture, so, we went ahead and set-up a syslog server, it has a lot of noise and more over i can't see any meaningful information like packet drops and 3 way tcp handshakes.

would sending the captures from the ASA to a tftp server, protects the format a as is shows up on the ASA FW and thus can be more useful ?

Best Answer

The packet capture feature stores data in pcap format, which can be read by Wireshark and other analysis tools. So, yes, that would probably be more useful for packet analysis than syslog messages.