Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
oxfordfirewall
New Contributor

diagnose sniffer packet

Hi,

 

hopefully simple answer, but when running a diagnose sniffer packet - what does the : udp XX represent ?

14.230079 10.1.2.3.11720 -> 10.7.27.9.8888: udp 72

 

 

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

It appears to be data length inside of UDP datagram. If you run a packet capture via GUI and download it then open it with Wireshark, you can see the same.

Philippe_Gagne
Contributor

Hi,

 

This is the captured size of the packet.  I saw it in Wireshark.

 

If you use "diag sniffer packet <int> <filter> 6 0 l" and then use fgt2eth.exe to convert the capture to Wireshark, the field "72" is the captured size.

 

Regards.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors