Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
oxfordfirewall
New Contributor

diagnose sniffer packet

Hi,

 

hopefully simple answer, but when running a diagnose sniffer packet - what does the : udp XX represent ?

14.230079 10.1.2.3.11720 -> 10.7.27.9.8888: udp 72

 

 

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

It appears to be data length inside of UDP datagram. If you run a packet capture via GUI and download it then open it with Wireshark, you can see the same.

Philippe_Gagne
Contributor

Hi,

 

This is the captured size of the packet.  I saw it in Wireshark.

 

If you use "diag sniffer packet <int> <filter> 6 0 l" and then use fgt2eth.exe to convert the capture to Wireshark, the field "72" is the captured size.

 

Regards.

Labels
Top Kudoed Authors