27.11.2012 Views

IronPort - daily management guide - AsyncOS 7.6.1

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Support Commands<br />

8-10<br />

Table 8-1 describes the packet capture settings you can configure.<br />

Table 8-1 Packet Capture Configuration Options<br />

Option Description<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email Daily Management Guide<br />

Chapter 8 Common Administrative Tasks<br />

Capture file size limit The maximum file size for all packet capture files in<br />

megabytes.<br />

Capture Duration Choose how long to run the packet capture:<br />

Run Capture Until File Size Limit Reached. The<br />

packet capture runs until the file size limit is reached.<br />

Run Capture Until Time Elapsed Reaches. The<br />

packet capture runs until the configured time has<br />

passed. You can enter the time in seconds (s), minutes<br />

(m), or hours (h). If you enter the amount of time without<br />

specifying the units, <strong>AsyncOS</strong> uses seconds by default.<br />

This option is only available in the GUI.<br />

Note The packet capture file is split into ten parts. If the<br />

file reaches the maximum size limit before the entire<br />

time has elapsed, the oldest part of the file is deleted<br />

(the data is discarded) and a new part starts with the<br />

current packet capture data. Only 1/10 of the packet<br />

capture file is discarded at a time.<br />

Run Capture Indefinitely. The packet capture runs<br />

until you manually stop it.<br />

Note If the file reaches the maximum size limit before you<br />

manually stop the packet capture, the oldest part of<br />

the file is deleted (the data is discarded) and a new<br />

part starts with the current packet capture data.<br />

You can always manually stop any packet capture.<br />

Interface Select the network interface on which to run the packet<br />

capture.<br />

Filters Choose whether or not to apply a filter to the packet capture<br />

to reduce the amount of data stored in the packet capture.<br />

You can use of the predefined filters to filter by port, client<br />

IP, or server IP (GUI only), or you can create a custom filter<br />

using any syntax supported by the Unix tcpdump command,<br />

such as host 10.10.10.10 && port 80.<br />

The client IP is the IP address of the machine connecting to<br />

the appliance, such as a mail client sending messages<br />

through the Email Security appliance.<br />

The server IP is the IP address of the machine to which the<br />

appliance is connecting, such as an Exchange server to<br />

which the appliance is delivering messages.<br />

You can use the client and server IP addresses to track traffic<br />

between a specific client and a specific server, with the<br />

Email Security appliance in the middle.<br />

OL-25138-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!