Capture Dropped Packets on Cisco Secure Firewall Threat Defense
An administrator must fix a network problem whereby traffic from the inside network to a webserver is not getting through an instance of Cisco Secure Firewall Threat Defense. Which command must the administrator use to capture packets to the webserver that are dropped by Secure Firewall Threat Defense and resolve the issue?
Community Votes
67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the specific command used to capture packets dropped by the firewall engine; the common trap is choosing an interface capture which only shows ingress/egress traffic, not explicitly dropped packets.
This guide explains how to capture dropped packets on a Cisco Secure Firewall Threat Defense instance. It establishes that using the asp-drop capture type is the correct method to identify packets dropped by the firewall engine.
Choosing option A because an interface capture on the inside interface will show the packet arriving, but it does not specifically isolate or identify packets that were dropped by the firewall.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option D uses thetype asp-drop capture, which is specifically designed to intercept and log packets that are dropped by the Accelerated Security Path (ASP) engine within the Cisco Secure Firewall Threat Defense. When troubleshooting why traffic is not getting through, identifying the exact packets being dropped by the firewall's inspection or access policies is crucial. The asp-drop all argument captures all types of ASP drops, providing visibility into why the webserver traffic is being blocked.Why the Other Options Are Wrong
Options A, B, and C use standard interface captures (int INSIDE or int OUTSIDE). While an ingress interface capture might show the packet arriving at the firewall, it does not filter for or indicate that the packet was subsequently dropped by the firewall's policies. Option C also incorrectly specifies the source port as 80 (tcp any 80), which is incorrect for client traffic originating from a random ephemeral port. Option B captures traffic on the outside interface, which dropped packets will never reach.Community Comment Notes
Some learners argued for interface captures, with one noting that option C "restricts the troubleshooting massively by saying that the client tcp source port must be 80." Another commenter misunderstood the ASP engine, claiming "ASP: Accelerated Security Path is a feature that “skips some checks on already established connections”", which is incorrect; the ASP engine handles all packet processing and is where drops occur. The consensus correctly identifies thatasp-drop is the required capture type for dropped packets. Official Reference
Exam Strategy
When a question explicitly asks to capture packets "dropped" by a Cisco firewall, look for the type asp-drop keyword in the capture command options. Standard interface captures only show traffic entering or leaving, not the firewall's drop decisions.