Networking-Blog

My WordPress Blog

Troubleshoot Connections through the PIX and ASA

Make sure logging is enabled. The logging level needs to be set to debug. Logging can be sent to various locations.
This example uses the ASA log buffer. You might need an external logging server in production environments.

ciscoasa(config)#logging enable
ciscoasa(config)#logging buffered debugging

The user pings the inside interface of the ASA (ping 192.168.1.1). This output is displayed.

ciscoasa#show logging

!— Output is suppressed.

%ASA-6-302020: Built ICMP connection for faddr 192.168.1.50/512
gaddr 192.168.1.1/0 laddr 192.168.1.1/0
%ASA-6-302021: Teardown ICMP connection for faddr 192.168.1.50/512
gaddr 192.168.1.1/0 laddr 192.168.1.1/0

!— The user IP address is 192.168.1.50.

ASA Capture Feature

The administrator needs to create an access-list that defines what traffic the ASA needs to capture. After the access-list is defined, the capture command incorporates the access-list and applies it to an interface.

ciscoasa(config)#access-list inside_test permit icmp any host 192.168.1.1
ciscoasa(config)#capture inside_interface access-list inside_test interface inside

The user pings the inside interface of the ASA (ping 192.168.1.1). This output is displayed.

ciscoasa#show capture inside_interface
1: 13:04:06.284897 192.168.1.50 > 192.168.1.1: icmp: echo request

!— The user IP address is 192.168.1.50.

Note: In order to download the capture file to a system such as ethereal, you can do it as this output shows.

!— Open an Internet Explorer and browse with this https link format:

https://[<pix_ip>/<asa_ip>]/capture/<capture name>/pcap

Refer to ASA/PIX: Packet Capturing using CLI and ASDM Configuration Example in order to know more about Packet Capturing in ASA.

Debug

The debug icmp trace command is used to capture the ICMP traffic of the user.

ciscoasa#debug icmp trace

The user pings the inside interface of the ASA (ping 192.168.1.1). This output is displayed on the console.

ciscoasa#

!— Output is suppressed.

ICMP echo request from 192.168.1.50 to 192.168.1.1 ID=512 seq=5120 len=32
ICMP echo reply from 192.168.1.1 to 192.168.1.50 ID=512 seq=5120 len=32

!— The user IP address is 192.168.1.50.

In order to disable debug icmp trace, use one of these commands:

no debug icmp trace
undebug icmp trace

undebug all

Monitor syslog messages.

Search for the source IP address of the user that you located in Step 1. The user initiates application X.
The ASA administrator issues the show logging command and views the output.

ciscoasa#show logging

!— Output is suppressed.

%ASA-7-609001: Built local-host inside:192.168.1.50
%ASA-6-305011: Built dynamic TCP translation from inside:192.168.1.50/1107
to outside:172.22.1.254/1025
%ASA-6-302013: Built outbound TCP connection 90 for outside:172.22.1.1/80
(172.22.1.1/80) to inside:192.168.1.50/1107 (172.22.1.254/1025)

The logs reveal that the destination IP address is 172.22.1.1,
the protocol is TCP, the destination port is HTTP/80, and that traffic is sent to the outside interface.

Modify the capture filters.

The access-list inside_test command was previously used and is used here.

ciscoasa(config)#access-list inside_test permit ip host 192.168.1.50 any

!— This ACL line captures all traffic from 192.168.1.50
!— that goes to or through the ASA.

ciscoasa(config)#access-list inside_test permit ip any host 192.168.1.50 any

!— This ACL line captures all traffic that leaves
!— the ASA and goes to 192.168.1.50.

ciscoasa(config)#no access-list inside_test permit icmp any host 192.168.1.1
ciscoasa(config)#clear capture inside_interface

!— Clears the previously logged data.
!— The no capture inside_interface removes/deletes the capture.

The user initiates application X. The ASA administrator then issues the show capture inside_interface command and views the output.

ciscoasa(config)#show capture inside_interface
1: 15:59:42.749152 192.168.1.50.1107 > 172.22.1.1.80:
S 3820777746:3820777746(0) win 65535 <mss 1460,nop,nop,sackOK>
2: 15:59:45.659145 192.168.1.50.1107 > 172.22.1.1.80:
S 3820777746:3820777746(0) win 65535 <mss 1460,nop,nop,sackOK>
3: 15:59:51.668742 192.168.1.50.1107 > 172.22.1.1.80:
S 3820777746:3820777746(0) win 65535 <mss 1460,nop,nop,sackOK>