Skip to main content
marypoppins
New Member
October 25, 2022
Question

Capture with AND logic

  • October 25, 2022
  • 1 reply
  • 1046 views

Dear All,

 

I should capture traffic between two host so AND logic is required. My problem is the cli diag sniffer would be a perfect tool but it cannot write captured packets to disk, while in the gui's network/capture packet can not make and AND logic between host :(

Is there any pure solution for a version 6.4? Or just some kind of log-the-terminal workaround?

 

thank you

1 reply

amouawad
Staff
Staff
October 25, 2022

There are tools available to convert the CLI capture of diag sniffer into a PCAP file (which is what I'm guessing you're after?). Some examples can be found here:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-import-diagnose-sniffer-packet-data-to/ta-p/191727

 

https://community.fortinet.com/t5/FortiGate/Technical-Note-How-to-import-diagnose-sniffer-packet-data-to/ta-p/193335?externalID=FD30877

 

If you upgrade to 7.2 you can use the same CLI filters in the GUI:

amouawad_0-1666695577856.png