![Cisco ASA 5512-X Скачать руководство пользователя страница 299](http://html.mh-extra.com/html/cisco/asa-5512-x/asa-5512-x_configuration-manual_63717299.webp)
13-11
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 13 Troubleshooting Connections and Resources
Testing Your Configuration
Procedure
Step 1
The command is complicated, so we shall break it down into parts. Start by choosing the interface and
protocol for the trace:
packet-tracer
input
ifc_name
{
icmp
|
tcp
|
udp
|
rawip
} [
inline-tag
tag
] ...
Where:
•
input
ifc_name
—The name of the interface from which to start the trace.
•
icmp
,
tcp
,
udp
,
rawip
—The protocol to use. “rawip” is raw IP, that is, IP packets that are not
TCP/UDP.
•
inline-tag
tag
—(Optional.) The security group tag value embedded in the Layer 2 CMD header.
Valid values range from 0 - 65533.
Step 2
Next, type in the source address and protocol criteria.
...{
sip
|
user
username
|
security-group
{
name
name
|
tag
tag
} |
fqdn
fqdn-string
}...
Where:
•
sip
—The source IPv4 or IPv6 address for the packet trace.
•
user
username
—The user identity in the format of domain\user. The most recently mapped address
for the user (if any) is used in the trace.
•
security-group
{
name
name
| tag
tag
}—The source security group based on the IP-SGT lookup for
Trustsec. You can specify a security group name or a tag number.
•
fqdn
fqdn-string
—The fully qualified domain name of the source host, IPv4 only.
Step 3
Next, type in the protocol characteristics.
•
ICMP—Enter the ICMP type (1-255), ICMP code (0-255), and optionally, the ICMP identifier. You
must use numbers for each variable, for example, 8 for echo.
...
type
code
[
ident
]...
•
TCP/UDP—Enter the source port number.
...
sport
...
•
Raw IP—Enter the protocol number, 0-255.
...
protocol
...
Step 4
Finally, type in the destination address criteria, destination port for TCP/UDP traces, and optional
keywords, and press Enter.
...{
dip
|
security-group
{
name
name
|
tag
tag
} |
fqdn
fqdn-string
}
dport
[
detailed
] [
xml
]
Where:
•
dip
—The destination IPv4 or IPv6 address for the packet trace.
•
security-group
{
name
name
| tag
tag
}—The destination security group based on the IP-SGT
lookup for Trustsec. You can specify a security group name or a tag number.
•
fqdn
fqdn-string
—The fully qualified domain name of the destination host, IPv4 only.
•
dport
—The destination port for TCP/UDP traces. Do not include this value for ICMP or raw IP
traces.
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...