8 Replies Latest reply on Dec 22, 2011 11:25 AM by timsilverline

    How do I capture ESP VPN traffic?  What port numbers do I use?

    brian_duvall

      I noticed when I turn on capturing unmonitored traffic that I am not currently collecting the ESP traffic from my firewalls vpn connections.  The question is it appears I removed application with ID 5114 so I have no clue what port its attempting to talk on.  I can't create an application that allows all ports on protocol ESP since ESP isnt an option.  I must have removed whatever application would have collected this data...anyone know?

       

      Here is what the conversation looks like:

                                                                         
      Date/Time                                                             63.80.103.34                                                                                                                   lax-er1-vg01.discovery.com  (198.147.15.4)                                                       BytesPackets
      4/8/2010 1:57:00 PM                                                    ESP                                                                                                         Random High Port                                                                                                                 Removed Application with ID 5114                                                     71.1 Kbytes386 packets
      4/8/2010 1:57:00 PM                                                    ESP                                                                                                         Removed Application with ID 27532                                                                                                                                              Random High Port                                                                                122.3 Kbytes574 packets
      4/8/2010 1:56:00 PM                                                    ESP                                                                                                         Removed Application with ID 27532                                                                                                                                              Random High Port                                                                                114.6 Kbytes563 packets
      4/8/2010 1:56:00 PM                                                    ESP                                                                                                         Random High Port                                                                                                                 Removed Application with ID 5114                                                     73.7 Kbytes387 packets
      4/8/2010 1:55:00 PM                                                    ESP                                                                                                         Random High Port                                                                                                                 Removed Application with ID 5114                                                     208.2 Kbytes721 packets
      4/8/2010 1:55:00 PM                                                    ESP                                                                                                         Removed Application with ID 27532                                                                                                                                              Random High Port                                                                                194.5 Kbytes913 packets
      4/8/2010 1:54:00 PM                                                    ESP                                                                                                         Removed Application with ID 27532                                                                                                                                              Random High Port                                                                                133.5 Kbytes642 packets
      4/8/2010 1:54:00 PM                                                    ESP                                                                                                         Random High Port                                                                                                                 Removed Application with ID 5114                                                     78.6 Kbytes467 packets
      4/8/2010 1:53:00 PM                                                    ESP                                                                                                         Random High Port                                                                                                                 Removed Application with ID 5114                                                     66.6 Kbytes345 packets
      4/8/2010 1:53:00 PM                                                    ESP                                                                                                         Removed Application with ID 27532                                                                                                                                              Random High Port                                                                                114.3 Kbytes

      539 packets