This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

How do I capture ESP VPN traffic? What port numbers do I use?

I noticed when I turn on capturing unmonitored traffic that I am not currently collecting the ESP traffic from my firewalls vpn connections.  The question is it appears I removed application with ID 5114 so I have no clue what port its attempting to talk on.  I can't create an application that allows all ports on protocol ESP since ESP isnt an option.  I must have removed whatever application would have collected this data...anyone know?

 

Here is what the conversation looks like:

Date/Time  63.80.103.34  lax-er1-vg01.discovery.com (198.147.15.4) Bytes Packets
4/8/2010 1:57:00 PM ESP Random High Port  Removed Application with ID 5114 71.1 Kbytes386 packets
4/8/2010 1:57:00 PM ESP Removed Application with ID 27532  Random High Port 122.3 Kbytes574 packets
4/8/2010 1:56:00 PM ESP Removed Application with ID 27532  Random High Port 114.6 Kbytes563 packets
4/8/2010 1:56:00 PM ESP Random High Port  Removed Application with ID 5114 73.7 Kbytes387 packets
4/8/2010 1:55:00 PM ESP Random High Port  Removed Application with ID 5114 208.2 Kbytes721 packets
4/8/2010 1:55:00 PM ESP Removed Application with ID 27532  Random High Port 194.5 Kbytes913 packets
4/8/2010 1:54:00 PM ESP Removed Application with ID 27532  Random High Port 133.5 Kbytes642 packets
4/8/2010 1:54:00 PM ESP Random High Port  Removed Application with ID 5114 78.6 Kbytes467 packets
4/8/2010 1:53:00 PM ESP Random High Port  Removed Application with ID 5114 66.6 Kbytes345 packets
4/8/2010 1:53:00 PM ESP Removed Application with ID 27532  Random High Port 114.3 Kbytes

539 packets