Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fruit_company
New Contributor

Packet capture in 5.2?

Hrm. Upgraded a little 60D dev firewall to 5.2 to give it a test drive. One of the first things I' ve noticed is that the packet capture menu that used to be under System > Network isn' t there any longer. I checked the 5.2 docs -- and it looks like that' s where it' s still *supposed* to be. Also checked the admin profile to make sure the super_admin profile still had " packet capture configuration" permissions (it does). Bug? Or am I just missing something.
1 Solution
emnoc
Esteemed Contributor III

https://x.x.x.x/p/firewall/sniffer/

 

Where x.x.x.x is your interface for mng-https.

 

 

 

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
12 REPLIES 12
AlexFeren
New Contributor III

rthomp wrote:
Has anyone seen this issue?  I do a packet capture  dia sniffer packet any "host 10.1.1.100" 4 and after one packet or two is displayed on the screen then it stops.  Is this a Fortigate setting that is preventing this?

Can't comment on "after one packet or two ... stops", however, FYI, as per Technical Note: Packet capture buffer limit there's a 2MB buffer limit.

 

Sean_Toomey_FTNT wrote:
Also don' t forget you can capture packets on a per-rule basis now!

Unfortunately, requires log disk - not useful on lower-end devices.

emnoc
Esteemed Contributor III

if the packet is being offloaded  on the NP than it highly likely you can't do a full packet sniffer.

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ndjathe
New Contributor

Please, how to capture ICMP packets from GUI?

Labels
Top Kudoed Authors