Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-users: Re: [Wireshark-users] Cisco FWSM Capture Dump

From: "Robert D. Scott" <robert@xxxxxxx>
Date: Mon, 10 Aug 2009 13:04:26 -0400
Are you running multiple contexts?  We do not normally allow http to a user
context on the fwsm>

Robert D. Scott                 Robert@xxxxxxx
Senior Network Engineer         352-273-0113 Phone
CNS - Network Services          352-392-2061 CNS Phone Tree
University of Florida           352-392-9440 FAX
Florida Lambda Rail             352-294-3571 FLR NOC
Gainesville, FL  32611          321-663-0421 Cell


-----Original Message-----
From: wireshark-users-bounces@xxxxxxxxxxxxx
[mailto:wireshark-users-bounces@xxxxxxxxxxxxx] On Behalf Of
NMaio@xxxxxxxxxxxx
Sent: Monday, August 10, 2009 12:56 PM
To: wireshark-users@xxxxxxxxxxxxx
Subject: Re: [Wireshark-users] Cisco FWSM Capture Dump

Robert,
Maybe I am misunderstanding you but I have done many captures on our
FWSMs.  After you let the capture run for a bit and grab the packets you
need you can just open a web browser to the interface on the context you
are capturing from.  For example.

https://10.x.x.x/capture/CONTEXT_NAME/CAPTURE_NAME/pcap

You can download the pcap file of the capture from here.

Give that a try.

Let me know if that works for you.
Nick