| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653 |
- <!DOCTYPE html>
- <html lang="en">
- <head>
- <meta charset="UTF-8">
- <meta http-equiv="X-UA-Compatible" content="IE=edge">
- <meta name="viewport" content="width=device-width, initial-scale=1.0">
- <meta name="generator" content="Asciidoctor 2.0.17">
- <title>ciscodump(1)</title>
- <link rel="stylesheet" href="./ws.css">
- </head>
- <body class="manpage">
- <div id="header">
- <h1>ciscodump(1) Manual Page</h1>
- <h2 id="_name">NAME</h2>
- <div class="sectionbody">
- <p>ciscodump - Provide interfaces to capture from a remote Cisco device through SSH.</p>
- </div>
- </div>
- <div id="content">
- <div class="sect1">
- <h2 id="_synopsis">SYNOPSIS</h2>
- <div class="sectionbody">
- <div class="paragraph">
- <p><span class="nowrap"><strong>ciscodump</strong></span>
- <span class="nowrap">[ <strong>--help</strong> ]</span>
- <span class="nowrap">[ <strong>--version</strong> ]</span>
- <span class="nowrap">[ <strong>--extcap-interfaces</strong> ]</span>
- <span class="nowrap">[ <strong>--extcap-dlts</strong> ]</span>
- <span class="nowrap">[ <strong>--extcap-interface</strong>=<interface> ]</span>
- <span class="nowrap">[ <strong>--extcap-config</strong> ]</span>
- <span class="nowrap">[ <strong>--extcap-capture-filter</strong>=<capture filter> ]</span>
- <span class="nowrap">[ <strong>--capture</strong> ]</span>
- <span class="nowrap">[ <strong>--fifo</strong>=<path to file or pipe> ]</span>
- <span class="nowrap">[ <strong>--remote-host</strong>=<IP address> ]</span>
- <span class="nowrap">[ <strong>--remote-port</strong>=<TCP port> ]</span>
- <span class="nowrap">[ <strong>--remote-username</strong>=<username> ]</span>
- <span class="nowrap">[ <strong>--remote-password</strong>=<password> ]</span>
- <span class="nowrap">[ <strong>--remote-filter</strong>=<filter> ]</span>
- <span class="nowrap">[ <strong>--sshkey</strong>=<public key path> ]</span>
- <span class="nowrap">[ <strong>--remote-interface</strong>=<interface> ]</span>
- <span class="nowrap">[ <strong>--remote-count</strong>=<count> ]</span></p>
- </div>
- <div class="paragraph">
- <p><span class="nowrap"><strong>ciscodump</strong></span>
- <span class="nowrap"><strong>--extcap-interfaces</strong></span></p>
- </div>
- <div class="paragraph">
- <p><span class="nowrap"><strong>ciscodump</strong></span>
- <span class="nowrap"><strong>--extcap-interface</strong>=ciscodump</span>
- <span class="nowrap"><strong>--extcap-dlts</strong></span></p>
- </div>
- <div class="paragraph">
- <p><span class="nowrap"><strong>ciscodump</strong></span>
- <span class="nowrap"><strong>--extcap-interface</strong>=ciscodump</span>
- <span class="nowrap"><strong>--extcap-config</strong></span></p>
- </div>
- <div class="paragraph">
- <p><span class="nowrap"><strong>ciscodump</strong></span>
- <span class="nowrap"><strong>--extcap-interface</strong>=ciscodump</span>
- <span class="nowrap"><strong>--fifo</strong>=<path to file or pipe></span>
- <span class="nowrap"><strong>--capture</strong></span>
- <span class="nowrap"><strong>--remote-host</strong>=remotedevice</span>
- <span class="nowrap"><strong>--remote-port</strong>=22</span>
- <span class="nowrap"><strong>--remote-username</strong>=user</span>
- <span class="nowrap"><strong>--remote-interface</strong>=<the device interface></span>
- <span class="nowrap"><strong>--remote-count</strong>=<count></span></p>
- </div>
- </div>
- </div>
- <div class="sect1">
- <h2 id="_description">DESCRIPTION</h2>
- <div class="sectionbody">
- <div class="paragraph">
- <p><strong>Ciscodump</strong> is an extcap tool that relies on Cisco EPC to allow a user to run a remote capture
- on a Cisco device in a SSH connection. It supports IOS, IOS-XE based device and ASA devices.</p>
- </div>
- <div class="paragraph">
- <p>The tool configures capture on the device, reads data and removes configuration from the device. Provided credentials must allow the tool to configure the device.</p>
- </div>
- <div class="paragraph">
- <p>When capture is started, packets are provided as they are received from the device. Capture stops when:</p>
- </div>
- <div class="ulist">
- <ul>
- <li>
- <p>requested count of packets is reached (<strong>--remote-count</strong> is mandatory)</p>
- </li>
- <li>
- <p>when capture finishes on the device (e.g. capture buffer is full)</p>
- </li>
- <li>
- <p>the capture is stopped by the user</p>
- </li>
- </ul>
- </div>
- <div class="paragraph">
- <p>Capture performance depends on a device type. The tool tries to read packets as soon as they received, but is usually slower than capturing device captures packets. Therefore packets are read in batches.</p>
- </div>
- <div class="paragraph">
- <p>IOS/IOS-XE provides only access to all captured packets from the top. Therefore reading of second batch means to read all packets from first batch, but ignore them and then read new packets in second batch.</p>
- </div>
- <div class="paragraph">
- <p>ASA provides access to specific packet so tool reads every packet just once.</p>
- </div>
- <div class="sect2">
- <h3 id="_supported_cisco_software">SUPPORTED CISCO SOFTWARE</h3>
- <div class="paragraph">
- <p>The application supports IOS version is 12.4 and higher. The IOS version supporting capture feature is 12.4(20)T and higher. More details can be
- found here: <a href="https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-embedded-packet-capture/datasheet_c78-502727.html" class="bare">https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-embedded-packet-capture/datasheet_c78-502727.html</a></p>
- </div>
- <div class="paragraph">
- <p>The application supports IOS-XE version 16.1 and higher. Search for "Embedded Packet Capture Configuration Guide, Cisco IOS XE" to get more details.</p>
- </div>
- <div class="paragraph">
- <p>The application supports ASA version 8.4 and higher. More details can be found here: <a href="https://community.cisco.com/t5/security-documents/asa-using-packet-capture-to-troubleshoot-asa-firewall/ta-p/3129889" class="bare">https://community.cisco.com/t5/security-documents/asa-using-packet-capture-to-troubleshoot-asa-firewall/ta-p/3129889</a></p>
- </div>
- </div>
- </div>
- </div>
- <div class="sect1">
- <h2 id="_options">OPTIONS</h2>
- <div class="sectionbody">
- <div class="dlist">
- <dl>
- <dt class="hdlist1">--help</dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>Print program arguments.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--version</dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>Print program version.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--extcap-interfaces</dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>List available interfaces.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--extcap-interface=<interface></dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>Use specified interfaces.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--extcap-dlts</dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>List DLTs of specified interface.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--extcap-config</dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>List configuration options of specified interface.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--capture</dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>Start capturing from specified interface and save it in place specified by --fifo.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--fifo=<path to file or pipe></dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>Save captured packet to file or send it through pipe.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--remote-host=<remote host></dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>The address of the remote host for capture.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--remote-port=<remote port></dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>The SSH port of the remote host.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--remote-username=<username></dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>The username for ssh authentication.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--remote-password=<password></dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>The password to use (if not ssh-agent and pubkey are used). WARNING: the
- passwords are stored in plaintext and visible to all users on this system. It is
- recommended to use keyfiles with a SSH agent.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--remote-filter=<filter></dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>The remote filter on the device. This is a capture filter that follows the Cisco
- standards.</p>
- </div>
- <div class="paragraph">
- <p>For IOS/IOS-XE see <a href="https://www.cisco.com/c/en/us/support/docs/ip/access-lists/26448-ACLsamples.html" class="bare">https://www.cisco.com/c/en/us/support/docs/ip/access-lists/26448-ACLsamples.html</a>.</p>
- </div>
- <div class="paragraph">
- <p>For ASA see <a href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/access-acls.html" class="bare">https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/access-acls.html</a>.</p>
- </div>
- <div class="paragraph">
- <p>Multiple filters can be specified using a comma between them. BEWARE: when using
- a filter, the default behavior is to drop all the packets except the ones that
- fall into the filter.</p>
- </div>
- <div class="paragraph">
- <p>Examples for IOS/IOS-XE:</p>
- </div>
- <div class="literalblock">
- <div class="content">
- <pre>permit ip host MYHOST any, permit ip any host MYHOST (capture the traffic for MYHOST)</pre>
- </div>
- </div>
- <div class="literalblock">
- <div class="content">
- <pre>deny ip host MYHOST any, deny ip any host MYHOST, permit ip any any (capture all the traffic except MYHOST)</pre>
- </div>
- </div>
- <div class="paragraph">
- <p>Examples for ASA:</p>
- </div>
- <div class="literalblock">
- <div class="content">
- <pre>permit any4 host MYHOST, permit host MYHOST any4 (capture IPv4 traffic for MYHOST)</pre>
- </div>
- </div>
- <div class="admonitionblock note">
- <table>
- <tr>
- <td class="icon">
- <div class="title">Note</div>
- </td>
- <td class="content">
- Different capture types support or do not support specific ACL keywords. The tool is not able to check it, just tries to configure it. If error occurs, the tool just reports it and terminates. Debris are left in configuration in this case.
- </td>
- </tr>
- </table>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--sshkey=<SSH private key path></dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>The path to a private key for authentication.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--remote-interface=<remote interface></dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>The remote network interface to capture from. One interface or list of interface names can be used. Iterfaces are separated by comma. Interface names must be supported by the device.</p>
- </div>
- <div class="paragraph">
- <p>There are interface names causing different capture types. They are specific to used Cisco software.</p>
- </div>
- <div class="paragraph">
- <p><strong>IOS special names</strong></p>
- </div>
- <div class="ulist">
- <ul>
- <li>
- <p><code>process-switched</code> - capture process switched packets in both directions</p>
- </li>
- <li>
- <p><code>from-us</code> - capture process switched packets originating at the device</p>
- </li>
- </ul>
- </div>
- <div class="paragraph">
- <p><strong>IOS-XE special names</strong></p>
- </div>
- <div class="ulist">
- <ul>
- <li>
- <p><code>control-plane</code> - captures in/out packets touching control plane</p>
- </li>
- </ul>
- </div>
- <div class="paragraph">
- <p><strong>ASA special names</strong></p>
- </div>
- <div class="ulist">
- <ul>
- <li>
- <p><code>asp-drop</code> - capture packets dropped by all asp categories</p>
- </li>
- <li>
- <p><code>TYPE---ifname</code> - syntax to refer ASA capture types, see <a href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/A-H/asa-command-ref-A-H/ca-cld-commands.html#wp2435483314" class="bare">https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/A-H/asa-command-ref-A-H/ca-cld-commands.html#wp2435483314</a></p>
- <div class="ulist">
- <ul>
- <li>
- <p><code>isakmp---ifname</code> - capture isakmp packets</p>
- </li>
- <li>
- <p><code>lacp---ifname</code> - capture lacp packets (just physical interfaces are supported)</p>
- </li>
- <li>
- <p><code>tls-proxy---ifname</code> - capture tls-proxy packets</p>
- </li>
- <li>
- <p><code>inline-tag---ifname</code> - capture all SGT tagget packets</p>
- </li>
- <li>
- <p><code>raw-data---ifname</code> - same as <code>ifname</code></p>
- </li>
- </ul>
- </div>
- </li>
- <li>
- <p>syntax to capture decrypted traffic for some of capture types:</p>
- <div class="ulist">
- <ul>
- <li>
- <p><code>isakmp/decrypted---ifname</code> - capture isakmp packets including decrypted payload</p>
- </li>
- <li>
- <p><code>tls-proxy/decrypted---ifname</code> - capture tls-proxy packets including decrypted payload</p>
- </li>
- <li>
- <p><code>inline-tag/decrypted---ifname</code> - capture inline-tag packets including decrypted payload</p>
- </li>
- <li>
- <p><code>raw-data/decrypted---ifname</code> - capture raw-data packets including decrypted payload</p>
- </li>
- </ul>
- </div>
- </li>
- </ul>
- </div>
- <div class="paragraph">
- <p>Use e. g. <code>isakmp/decrypted---outside</code> to capture encrypted and decrypted isakmp traffic on <code>outside</code> interface.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--remote-count=<count></dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>Count of packets to capture. Capture is stopped when count is reached.</p>
- </div>
- </div>
- </div>
- </dd>
- <dt class="hdlist1">--extcap-capture-filter=<capture filter></dt>
- <dd>
- <div class="openblock">
- <div class="content">
- <div class="paragraph">
- <p>Unused (compatibility only).</p>
- </div>
- </div>
- </div>
- </dd>
- </dl>
- </div>
- </div>
- </div>
- <div class="sect1">
- <h2 id="_examples">EXAMPLES</h2>
- <div class="sectionbody">
- <div class="paragraph">
- <p>To see program arguments:</p>
- </div>
- <div class="literalblock">
- <div class="content">
- <pre>ciscodump --help</pre>
- </div>
- </div>
- <div class="paragraph">
- <p>To see program version:</p>
- </div>
- <div class="literalblock">
- <div class="content">
- <pre>ciscodump --version</pre>
- </div>
- </div>
- <div class="paragraph">
- <p>To see interfaces:</p>
- </div>
- <div class="literalblock">
- <div class="content">
- <pre>ciscodump --extcap-interfaces</pre>
- </div>
- </div>
- <div class="paragraph">
- <p>Only one interface (ciscodump) is supported.</p>
- </div>
- <div class="literalblock">
- <div class="title">Example output</div>
- <div class="content">
- <pre>interface {value=ciscodump}{display=SSH remote capture}</pre>
- </div>
- </div>
- <div class="paragraph">
- <p>To see interface DLTs:</p>
- </div>
- <div class="literalblock">
- <div class="content">
- <pre>ciscodump --extcap-interface=ciscodump --extcap-dlts</pre>
- </div>
- </div>
- <div class="literalblock">
- <div class="title">Example output</div>
- <div class="content">
- <pre>dlt {number=147}{name=ciscodump}{display=Remote capture dependent DLT}</pre>
- </div>
- </div>
- <div class="paragraph">
- <p>To see interface configuration options:</p>
- </div>
- <div class="literalblock">
- <div class="content">
- <pre>ciscodump --extcap-interface=ciscodump --extcap-config</pre>
- </div>
- </div>
- <div class="literalblock">
- <div class="title">Example output</div>
- <div class="content">
- <pre>ciscodump --extcap-interface=ciscodump --extcap-config
- arg {number=0}{call=--remote-host}{display=Remote SSH server address}
- {type=string}{tooltip=The remote SSH host. It can be both an IP address or a hostname}
- {required=true}{group=Server}
- arg {number=1}{call=--remote-port}{display=Remote SSH server port}
- {type=unsigned}{default=22}{tooltip=The remote SSH host port (1-65535)}
- {range=1,65535}{group=Server}
- arg {number=2}{call=--remote-username}{display=Remote SSH server username}
- {type=string}{default=<current user>}{tooltip=The remote SSH username. If not provided, the current user will be used}
- {group=Authentication}
- arg {number=3}{call=--remote-password}{display=Remote SSH server password}
- {type=password}{tooltip=The SSH password, used when other methods (SSH agent or key files) are unavailable.}
- {group=Authentication}
- arg {number=4}{call=--sshkey}{display=Path to SSH private key}
- {type=fileselect}{tooltip=The path on the local filesystem of the private ssh key}
- {group=Authentication}
- arg {number=5}{call=--proxycommand}{display=ProxyCommand}
- {type=string}{tooltip=The command to use as proxy for the SSH connection}{group=Authentication}
- arg {number=6}{call--sshkey-passphrase}{display=SSH key passphrase}
- {type=password}{tooltip=Passphrase to unlock the SSH private key}{group=Authentication
- arg {number=7}{call=--remote-interface}{display=Remote interface}
- {type=string}{tooltip=The remote network interface used for capture}
- {required=true}{group=Capture}
- arg {number=8}{call=--remote-filter}{display=Remote capture filter}
- {type=string}{tooltip=The remote capture filter}{default=<filter to exclude current host>}
- {group=Capture}
- arg {number=9}{call=--remote-count}{display=Packets to capture}
- {type=unsigned}{tooltip=The number of remote packets to capture.}
- {required=true}{group=Capture}
- arg {number=10}{call=--debug}{display=Run in debug mode}
- {type=boolflag}{default=false}{tooltip=Print debug messages}
- {required=false}{group=Debug}
- arg {number=11}{call=--debug-file}{display=Use a file for debug}
- {type=string}{tooltip=Set a file where the debug messages are written}
- {required=false}{group=Debug}</pre>
- </div>
- </div>
- <div class="paragraph">
- <p>To capture on IOS/IOS-XE:</p>
- </div>
- <div class="literalblock">
- <div class="content">
- <pre>ciscodump --extcap-interface ciscodump --fifo=/tmp/cisco.pcap --capture --remote-host 192.168.1.10
- --remote-username user --remote-interface gigabit0/0,gigiabit0/1
- --remote-filter "permit ip host 192.168.1.1 any, permit ip any host 192.168.1.1"
- --remote-count=10</pre>
- </div>
- </div>
- <div class="paragraph">
- <p>To capture on IOS/IOS-XE:</p>
- </div>
- <div class="literalblock">
- <div class="content">
- <pre>ciscodump --extcap-interface ciscodump --fifo=/tmp/cisco.pcap --capture --remote-host 192.168.1.10
- --remote-username user --remote-interface outside,dmz
- --remote-filter "permit host 192.168.1.1 any4, permit any4 host 192.168.1.1"
- --remote-count=10</pre>
- </div>
- </div>
- <div class="literalblock">
- <div class="content">
- <pre>ciscodump --extcap-interface ciscodump --fifo=/tmp/cisco.pcap --capture --remote-host 192.168.1.10
- --remote-username user --remote-interface raw-data/decrypted---outside
- --remote-filter "permit host 192.168.1.1 any4, permit any4 host 192.168.1.1"</pre>
- </div>
- </div>
- </div>
- </div>
- <div class="sect1">
- <h2 id="_known_issues">KNOWN ISSUES</h2>
- <div class="sectionbody">
- <div class="paragraph">
- <p>When capture stopped by the user before it finishes on Windows platform, configuration is not cleared on the device. Next run will probably fails because parts of configuration already exists on the device.</p>
- </div>
- <div class="paragraph">
- <p>Reading performance on IOS/IOS-XE is poor because re-reading of capture buffer over and over.</p>
- </div>
- <div class="paragraph">
- <p>The configuration of the capture on the device is a multi-step process. If the SSH connection is interrupted during
- it, the configuration can be in an inconsistent state. That can happen also if the capture is stopped and ciscodump
- can’t clean the configuration up. In this case it is necessary to log into the device and manually clean the
- configuration, removing configuration elements:</p>
- </div>
- <div class="ulist">
- <ul>
- <li>
- <p>IOS</p>
- <div class="ulist">
- <ul>
- <li>
- <p>capture points WSC_P_<number> (depends on count of capture interfaces)</p>
- </li>
- <li>
- <p>the capture buffer WSC_B</p>
- </li>
- <li>
- <p>the capture capture acl WSC_ACL (if filter was used)</p>
- </li>
- </ul>
- </div>
- </li>
- <li>
- <p>IOS-XE</p>
- <div class="ulist">
- <ul>
- <li>
- <p>the capture WSC</p>
- </li>
- <li>
- <p>the capture capture acl WSC_ACL (if filter was used)</p>
- </li>
- </ul>
- </div>
- </li>
- <li>
- <p>ASA</p>
- <div class="ulist">
- <ul>
- <li>
- <p>the capture WSC</p>
- </li>
- <li>
- <p>the capture capture acl WSC_ACL (if filter was used)</p>
- </li>
- </ul>
- </div>
- </li>
- </ul>
- </div>
- <div class="paragraph">
- <p>On IOS platforms, only IPv4 commands issued and only IPv4 packets are captured.</p>
- </div>
- </div>
- </div>
- <div class="sect1">
- <h2 id="_see_also">SEE ALSO</h2>
- <div class="sectionbody">
- <div class="paragraph">
- <p><a href="wireshark.html">wireshark</a>(1), <a href="tshark.html">tshark</a>(1), <a href="dumpcap.html">dumpcap</a>(1), <a href="extcap.html">extcap</a>(4), <a href="sshdump.html">sshdump</a>(1)</p>
- </div>
- </div>
- </div>
- <div class="sect1">
- <h2 id="_notes">NOTES</h2>
- <div class="sectionbody">
- <div class="paragraph">
- <p><strong>ciscodump</strong> is part of the <strong>Wireshark</strong> distribution. The latest version
- of <strong>Wireshark</strong> can be found at <a href="https://www.wireshark.org" class="bare">https://www.wireshark.org</a>.</p>
- </div>
- <div class="paragraph">
- <p>HTML versions of the Wireshark project man pages are available at
- <a href="https://www.wireshark.org/docs/man-pages" class="bare">https://www.wireshark.org/docs/man-pages</a>.</p>
- </div>
- </div>
- </div>
- <div class="sect1">
- <h2 id="_authors">AUTHORS</h2>
- <div class="sectionbody">
- <div class="paragraph">
- <div class="title">Original Author</div>
- <p>Dario Lombardo <lomato[AT]gmail.com></p>
- </div>
- </div>
- </div>
- </div>
- </body>
- </html>
|