QuestionQ40

Security profiles

During the maintenance window, you need to sniff all traffic passing through a particular firewall policy that is processed by NP6 interfaces. The sniffer trace output contains only a few packets.

Why is the sniffer trace output limited?

  • A auto-asic-offload is set to enable in the firewall policy.
  • B The option npudbg is not added in the diagnose sniff packet command.
  • C This is an ultralow latency interface.
  • D inspection-mode is set to proxy in the firewall policy.
Explanation

With auto-asic-offload enabled, traffic accepted by the firewall policy can be offloaded to the NP6 processor. Offloaded traffic does not pass through the CPU-based packet sniffer, so the trace shows only the packets that are not offloaded. To capture all policy traffic with a standard sniffer, temporarily disable auto-asic-offload for that policy.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!