Created on 08-03-2021 10:43 PM Edited on 01-31-2024 05:12 AM By Jean-Philippe_P
Description
This article describes how to capture the packets of the client during communication across multiple IPs at the policy level.
Scope
FortiGate. See the bottom of the article for a list of situations in which this feature is not available.
Solution
In FortiOS 6.2 and above, policies have a 'Capture Packets' option under Logging Options.
To analyze or troubleshoot the issues, it is possible to use FortiOS' built-in packet sniffer or packet capture option available for the specific interface.
In the above cases, it is necessary to have specific filters to capture the traffic. Otherwise, all traffic passing through the respective interfaces will be captured.
In some scenarios, an application is trying to reach the actual destination IPs to identify communication issues of real time applications like Skype, Teams, Outlook, or any non-functioning websites.
Follow the steps below to capture the traffic flow through FortiGate of a specific source while it is trying to reach an application server or a non-functioning website:
Feature unavailability:
This feature may be unavailable in some cases. This feature is not available when the device does not have internal storage. For example: 60E, 60F and FortiWiFi 60F do not have this feature.
To check whether the device has internal storage, run the following command:
exe disk list
If the output appears blank, the device does not have internal storage. The following output is expected if the device has internal storage:
Disk HDD1 ref: 255 447.1GiB type: SSD [ATA ADATA SX1000L] dev: /dev/sda
partition ref: 1 440.1GiB, 439.0GiB free mounted: Y label: LOGUSEDX61BA3018 dev: /dev/sda1 start: 2048
Maximum policy packet capture-size can be altered with the following CLI configuration:
config log disk setting
set max-policy-packet-capture-size ?
<integer> please input integer value, range: 0-120186
Related article:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.