Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jai_Kishore
New Contributor

Packet capture

Hi All, Thanks in advance I have fortigate 620B in cluster mode and a fortianalyzer 100C.In this firewall there is no option of packet capture.I raised a ticket with fortinet team,They said there is no local disk in this firewall so there is no packet capture option. Now my question is,is there any way to enable like wireshark or netview kind of packet loggers in this firewall or with any 3rd party servers(which is installed with wireshark or netview) so that the firewall send the packets to this server. Regards, Jai Kishore
5 REPLIES 5
jorge9090
New Contributor

Good day Jai, What version of FortiOS is the cluster running? How deep do you want to scan the packets? You can always use the diagnose sniffer packet command in the interface you want to monitor.
mmar5540
New Contributor

Hi Jai, as jorge9090 write you can use diagnose sniffer command and turn on session logging to a log file (for example if you use PuTTy ), so you can later look at that capture.
Jai_Kishore
New Contributor

Hi jorge9090, Thanks for your reply.I am using FortiOS 5.0 (Patch7).I know there is in built packet capture.but I want to see particular interface,particular packet and particular src and dst,if any packet is blocked due to any IPS or AV like that.And how the packet is modifying from interface to interface. These features can be seen in wireshark. Is there any way to see like that in fortigate firewall. Regards, Jai Kishore
Istvan_Takacs_FTNT

Run ' diagnose sniffer packet' with the desired parameters to filter for the traffic you are interested in. Fortinet created a script (fgt2eth.pl) and application that takes text output of this sniffer command and parses it into tcpdump format (.cap) which you can later open in Wireshark. Using the FortiOS built-in packet sniffer http://kb.fortinet.com/kb/documentLink.do?externalID=11186&languageId
norouzi
Contributor

If you want to see blocked users, there is a part on the GUI.

Users> Monitor> Banned Users

There is a column about reason of blocking the user or IP address.

Labels
Top Kudoed Authors