Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Packet capture
Hi All,
Thanks in advance
I have fortigate 620B in cluster mode and a fortianalyzer 100C.In this firewall there is no option of packet capture.I raised a ticket with fortinet team,They said there is no local disk in this firewall so there is no packet capture option.
Now my question is,is there any way to enable like wireshark or netview kind of packet loggers in this firewall or with any 3rd party servers(which is installed with wireshark or netview) so that the firewall send the packets to this server.
Regards,
Jai Kishore
5 REPLIES 5
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good day Jai,
What version of FortiOS is the cluster running? How deep do you want to scan the packets?
You can always use the diagnose sniffer packet command in the interface you want to monitor.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Jai,
as jorge9090 write you can use diagnose sniffer command and turn on session logging to a log file (for example if you use PuTTy ), so you can later look at that capture.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi jorge9090,
Thanks for your reply.I am using FortiOS 5.0 (Patch7).I know there is in built packet capture.but I want to see particular interface,particular packet and particular src and dst,if any packet is blocked due to any IPS or AV like that.And how the packet is modifying from interface to interface.
These features can be seen in wireshark. Is there any way to see like that in fortigate firewall.
Regards,
Jai Kishore
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Run ' diagnose sniffer packet' with the desired parameters to filter for the traffic you are interested in.
Fortinet created a script (fgt2eth.pl) and application that takes text output of this sniffer command and parses it into tcpdump format (.cap) which you can later open in Wireshark.
Using the FortiOS built-in packet sniffer
http://kb.fortinet.com/kb/documentLink.do?externalID=11186&languageId
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you want to see blocked users, there is a part on the GUI.
Users> Monitor> Banned Users
There is a column about reason of blocking the user or IP address.