On Tue, Sep 09, 2014 at 03:46:28PM +0200, Christian Schmit wrote: > - SPAN: on the ASR1000 SPAN does not seem to offer the possibility to > apply an IP access list to the SPAN session > - EPC: EPC can only collect data until the buffer is full which is by far > to small if a session needs to be captured/monitored over weeks > - LI feature: For using the lawful intercept (LI) feature of the ASR a > mediation device is required which we do not have
I'd have a look at the LI feature - In the end it'll only be packets encapsulated in some interesting header. My bet is somewhere on the net you'll find documentation or some implementation which is less than 1000 lines of C :) Flo -- Florian Lohoff [email protected]
signature.asc
Description: Digital signature
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
