This afternoon I upgraded from 7.0.15 to 7.2.10 and to my surprise the packet capture GUI changed to complete garbage. Not only that, I have lost the ability to capture multiple interfaces like before.
Is there any way to get the ability to capture multiple interfaces into their own pcaps like before?
Maybe it is hidden in the cli somehow?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Please refer to this article for packet capture using GUI:- https://docs.fortinet.com/index.php/document/fortigate/7.2.0/administration-guide/462154
you can also capture packets via CLI:- https://docs.fortinet.com/document/fortiweb/7.6.0/troubleshooting-guide/715676/packet-capture-via-c...
Yes there has been changes in the layout, but you can still run the parallel packet captures on the GUI.
You just will have to go to Diagnostics under Network, and start on new capture, close it, and then start it again on different interface.
This change was necessary/desirable to avoid lots of "duplicate message" (in red or black) in Wireshark view.
In other words, use "diag sniffer packet any .... 4 0 l" in CLI if you need to see how one packet comes in/through/out the chain of interfaces.
Toshi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1661 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.