Forum Discussion
How to capture corresponding server side connection for a specific client ip when using SNAT. (Ver. 10.2.4)
Using V.10.2.4, VS configured with no persistence profile and using SNAT. How can I capture the server side traffic corresponding to a specific Client IP when using SNAT ? I've read that there are some extra tcpdump features in newer versions but am stuck on 10.2.4 for the moment. Do I need an iRule ?
2 Replies
- Kevin_Stewart
Employee
The -p flag was introduced in 11.2 (I believe) to enable capturing peer flows. Prior to that it's a bit tricky. Please review the following for more information on pre-11.2 options:
sol11555: Gathering data in preparation for a traffic impacting change to the BIG-IP system
Here's an interesting thread that describes the peer flow option in 11.2:
https://devcentral.f5.com/questions/tcpdump-with-snat
- nitass
Employee
in case you want to try wireshark plugin.
F5 Wireshark Plugin
https://devcentral.f5.com/wiki/AdvDesignConfig.F5WiresharkPlugin.ashxplugin file
https://devcentral.f5.com/questions/f5-wireshark-plugin
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com