PCAP with only source IP Filter and Global counters

Showing results for 
Search instead for 
Did you mean: 

PCAP with only source IP Filter and Global counters

Cyber Elite
Cyber Elite


Hi Everyone,


For certian cloud apps we do not know specific destination IP as users have given is list of urls and multiple subnets.

My question is if we do PCAP with only source IP as filter and then do the PCAP and check the global counters for error or

drops will we see right matched traffic as dropped in global counters?




To see right drops in global counters we whould filter via both source and destion ip ?


L5 Sessionator

Hey Mike,


Most of the time I test from some test laptop that has not much software on it (to reduce the chatter) then do the packet filter against the source IP and DST IP to capture all destination traffic. If there is some issue with the cloud service and you see drops in the counters, likely they are related *but* not 100%.


The most full way of doing this would be to do an nslookup at the time to the cloud service to get the destination IP to use in your filter. Even though; yes, the IP address is dynamic, it should not be changing during the duration of your debugging.




Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!