Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fruit_company
New Contributor

Packet capture in 5.2?

Hrm. Upgraded a little 60D dev firewall to 5.2 to give it a test drive. One of the first things I' ve noticed is that the packet capture menu that used to be under System > Network isn' t there any longer. I checked the 5.2 docs -- and it looks like that' s where it' s still *supposed* to be. Also checked the admin profile to make sure the super_admin profile still had " packet capture configuration" permissions (it does). Bug? Or am I just missing something.
1 Solution
emnoc
Esteemed Contributor III

https://x.x.x.x/p/firewall/sniffer/

 

Where x.x.x.x is your interface for mng-https.

 

 

 

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
12 REPLIES 12
AlexFeren
New Contributor III

rthomp wrote:
Has anyone seen this issue?  I do a packet capture  dia sniffer packet any "host 10.1.1.100" 4 and after one packet or two is displayed on the screen then it stops.  Is this a Fortigate setting that is preventing this?

Can't comment on "after one packet or two ... stops", however, FYI, as per Technical Note: Packet capture buffer limit there's a 2MB buffer limit.

 

Sean_Toomey_FTNT wrote:
Also don' t forget you can capture packets on a per-rule basis now!

Unfortunately, requires log disk - not useful on lower-end devices.

emnoc
Esteemed Contributor III

if the packet is being offloaded  on the NP than it highly likely you can't do a full packet sniffer.

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ndjathe
New Contributor

Please, how to capture ICMP packets from GUI?

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors