| Using a Cisco Router as a “Remote Collector” for tcpdump or Wireshark |
| Source: SANS - Posted by Anthony Pell | ||
|
As you've probably guessed, the answer is YES, or else there’d be no reason to write this article. Let's go through the steps, from start to finish. First, ensure that you have syslog set up – your packets are going to show up in the router’s log. You can execute this packet capture process without syslog by using “show log” to view the local log buffer, but you'll be very limited as to how many packets you can capture per session. Read this full article at SANS
Only registered users can write comments. Powered by AkoComment! |
||