Skip to main content
journeyman
New Member
January 8, 2018
Solved

diagnostic packet capture incomplete - any tips to improve?

  • January 8, 2018
  • 6 replies
  • 16023 views

Does anyone know how to improve the completeness of the diagnostic sniffer? Is there some system type setting that impacts this functionality?

 

I have noticed the output of the diagnostic sniffer often seems to only include session establishment type traffic, or perhaps it deliberately excludes in-session traffic (TCP obviously). I noticed this more often using capture level 4 (header and interface). Level 6 (bytes and interface) seems to more often include in-session traffic, but not in my current scenario.

The diagnose doco site does not mention anything about this although I'm sure I've seen disclaimers somewhere.

 

Currently I am fault-finding an application issue and packets I know are traversing a firewall are not being logged. I do see arp, session establishment and teardown, but not session traffic, and in this case I need to see that.

I am using commands of the form:

diagnose sniffer packet internal1 'host a.b.c.d' 6 0 a
The hardware is 60C, the unit is very lightly loaded (CPU usage is not an issue) and the traffic I'm trying to log is of the order of less than a packet per second.

    Best answer by emnoc

    A  FGT60C has no ASIC  out of a SOC ( SystemOnChip ) so I don't think you can disable that but give the commands a try.

     

    I would  1st run a diag debug flow and look at the flow statistics.

     

    6 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    January 8, 2018

    Are you sure you disabled asic offloading at the policy?

     set auto-asic-offload disable

    emnoc
    emnocAnswer
    New Member
    January 8, 2018

    A  FGT60C has no ASIC  out of a SOC ( SystemOnChip ) so I don't think you can disable that but give the commands a try.

     

    I would  1st run a diag debug flow and look at the flow statistics.

     

    journeyman
    New Member
    January 9, 2018

    Thankyou! Like emnoc I wasn't expecting this to work but it did.

    set auto-asic-offload disable in the policy results in full traffic logging in the sniffer (effective immediately the policy is changed). This setting was default enable and not visible without show full.

    Very, very useful to know.

     

    Question - should I leave the policy running auto-asic-offload disable, or only change that when logging is required?

     

    FWIW, the trace only shows the same packets as the sniffer when the policy has the default setting of auto-asic-offload enable.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!