Created on
08-29-2019
01:13 AM
Edited on
11-04-2024
09:30 AM
By
Adam_Shortt_FTN
Description
This article describes how to use the built-in packet capture feature in FortiOS from the GUI interface.
Scope
FortiGate.
Solution
On the 5.6 firmware branch, the unit needs a disk and logging to disk has to be enabled.
Since the firmware version 6.0.2, this restriction has been removed.
Here is the Step-by-Step guide to capturing packets from GUI:
The option to capture the packet based on interface and filter by hosts, ports or VLANs will be proposed.
In the example above 100 packets would be captured based on the selected filters:
IP address 10.205.1.206 and port 80,443 on interface port 3.
If 'Enable Filters' is not selected, all packets on the selected interface will be captured.
Results.
Packet capture can tell what is happening on the network at a low level. This can be very useful for troubleshooting problems, such as:
Limitations:
On FortiGate v7.2+ this option can be found under Network -> Diagnostics.
On FortiGate v7.2+, it is not possible to run several packet captures at the same time. On the new packet capture module, if the administrator will logout from the FortiGate GUI, the packet capture will stop running as well.
An alternative way to do background packet capture is through SSH/CLI, using the below command:
diag sniffer packet <interface name> "<filter>" 6 0 l
On FortiGate v7.4.3, it is re-introduced the possibility to run several packet captures simultaneously (maximum 15 captures) and there is a limitation on the number of packets to 20.000.
Starting FortiOS v7.4.4, packet capture criteria can now be stored. Once settings have been configured, it is now possible to choose to Start capture, Save settings for later, or Close.
Related documents:
Packet capture
Embed real-time packet capture and analysis tool on Diagnostics page
Run simultaneous packet captures and use the command palette
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.