The migsock sniff utility is an advanced diagnostic tool for observing packets near the FortiOS ingress processing path. It provides visibility into traffic before it is affected by many higher-level policy and security inspection stages and is primarily intended for TAC and development-assisted troubleshooting.
When a migsock sniff session is started, packet information is mirrored from the ingress path and forwarded through the migration socket to a user-space diagnostic process for analysis.
Common use cases include:
Verifying packet arrival when interface statistics appear inaccurate. Troubleshooting NPU/NP7 hardware-offload visibility issues. Investigating discrepancies between dashboard statistics and actual traffic flow. Troubleshooting VLAN, virtual-switch, or hard-switch forwarding anomalies. Comparing software-observed traffic with hardware-forwarded traffic. Assisting with kernel-level packet-path investigations.
Migsock sniff is particularly useful when traffic is known to be flowing through the device, but interface counters, dashboard widgets, or other software-based statistics do not accurately reflect the observed traffic volume. Because migsock operates at a low level within the packet-processing path, it should be used only for advanced troubleshooting and may increase CPU utilization on busy systems.
Commands:
diagnose sniff migsock filter "< > "
diagnose sniff migsock ssl-trace enable
diagnose sniff migsock timestamp enable
diagnose sniff migsock debug-trace enable
diagnose sniff migsock start
Press 'CTRL+C' to stop
If the issue persists, contact Fortinet Support for further assistance.
|