FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
krodriguez
Staff
Staff
Article Id 404434
Description

This article describes how to do packet capture via GUI using an admin with Read-Write permission on Packet Capture only.

 

Starting FortiOS v7.4 and above, when a FortiGate that is managed by FortiManager (Login Mode: Read-Only), for an admin with Read-Write permission on packet capture only to work on the GUI, an admin user with Read-Write permission (at least on system configuration and packet capture) needs to save the packet capture settings.

Scope FortiOS v7.4 and above.
Solution

Admin pcap-admin will be assigned to the admin profile pcap_profile that has Read-Write only permission on packet capture.

 

krodriguez_27-1754020972749.png

 

krodriguez_28-1754020972750.png

 

  1. Log in to FortiGate using an admin with Read-Write permission and Login Mode: Read-Write (default admin with super_admin permission will be used in this KB article).

 

  1. Go to Network -> Diagnostics -> New Packet Capture.

krodriguez_29-1754020972759.png

 

  1. Set the interface and filters as intended.

  2. When Saving, select either Start capture or Save settings for later.
                                                              
krodriguez_30-1754020972762.png

 

Packet capture saved.

 

krodriguez_31-1754020972765.png

 

  1. Log in using pcap-admin. Packet capture that is configured/saved by Read-Write admin is now available.
                                                               

krodriguez_32-1754020972770.png