📅 Wednesday, 3 September 2025

🕐 12:48 AM

  • Don’t need to live troubleshoot for a pcap all the time

  • Below mimics traffic from a src to a dest via a telnet command

  • Must be done on the closest firewall to the user traffic for it to work as it need to be from a source that it knows

  • SSH to firewall

  • Run below command template

FW01 $ execute telnet-options source

FW01 $ execute telnet

  • Run a clone session on the same firewall and run the pcap on this WHILE the telnet is running

FW01 $ diag sniffer packet any “pcap ip details” 4 0 l