Packet capture from Cisco ASA

August 18th, 2014

One of my favorite troubleshooting tools on the Cisco ASA firewall is doing a packet capture. An incoming packet will hit the capture before any ACL or NAT or other processing. An outgoing packet will hit a capture last before being put on the wire.

To start the capture, use this command


To view the capture from CLI

To download the pcap file

Or from your browser

To clear the capture

And finally, to remove the capture

Happy sniffing!

Categories: Networking