I see this "Capture packets" option while defining policies. How do I use it?
The feature causes the FortiGate to log a capture file for each session matching the policy
.I haven't had to test the feature to see where the capture files end up. I think from memory that the log entry for a session should contain a link to the local (or remote) location of the file for download and local viewing.
Regards, Chris McMullan Fortinet Ottawa
That sounds correct, I read somewhere that it goes to the logs. I've been checking under Log and report -> Traffic log -> Sniffer traffic, but theres nothing there and the rule I enabled "Capture packets" on has been getting hits. Not sure where else to look. We have FortiAnalyzer setup and the Fortigate is logging to it as well. I dont see anywhere on FortiAnalyzer that the captured data would show up tho.
Bumping this thread. Running 5.4.2 and cant find where to display/download the captured packets still.
I tested to enable "Capture Traffic" inside on of my policies.
It shows up in the logs.
FortiGate 100D with 5.4.3
FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C
Ok. Not seeing that on mine. I am using FortiAnalyzer so that may have something to do with it...
Did you tried it like described in the KB?
http://kb.fortinet.com/kb/documentLink.do?externalID=FD38914
This worked for me.
Yes, those were the directions I followed. May have something to do with running FortiAnalyzer but not sure. I looked there as well but no love.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1751 | |
1114 | |
766 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.