Fortinet white logo
Fortinet white logo

Administration Guide

Packet capture

Packet capture

Packets can be captured on configured interfaces by going to System > Network > Packet Capture.

The following information is available:

Column

Description

Interface

The name of the configured interface for which packets can be captured.

For information on configuring an interface, see Configuring network interfaces.

Filter Criteria

The values used to filter the packet.

# Packets

The number of packets.

Maximum Packet Count

The maximum number of packets that can be captured on a sniffer.

Progress

The status of the packet capture process.

Actions

Allows you to start and stop the capturing process, and download the most recently captured packets.

To start capturing packets on an interface, select the Start capturing button in the Actions column for that interface. The Progress column changes to Running, and the Stop capturing and Download buttons become available in the Actions column.

To add a packet sniffer:
  1. From the Packet Capture table, click Create New.

    The Create New Sniffer pane displays.

  2. Configure the following options:

    Option

    Description

    Interface

    The interface name (non-changeable).

    Max. Packets to Save

    Enter the maximum number of packets to capture, between 1-10000. The default is 4000 packets.

    Include IPv6 Packets

    Select to include IPv6 packets when capturing packets.

    Include Non-IP Packets

    Select to include non-IP packets when capturing packets.

    Enable Filters

    You can filter the packet by Host(s), Port(s), VLAN(s), and Protocol.

  3. Click OK.

To download captured packets:
  1. In the Actions column, click Download for the interface whose captured packets you want to download.

    If no packets have been captured for that interface, click Start capturing.

  2. When prompted, save the packet file (sniffer_[interface].pcap) to your management computer.

    The file can then be opened using packet analyzer software.

To edit a packet sniffer:
  1. From the Packet Capture table, click Edit.

    The Edit Sniffer pane displays.

  2. Configure the packet sniffer options

  3. Click OK.

Packet capture

Packet capture

Packets can be captured on configured interfaces by going to System > Network > Packet Capture.

The following information is available:

Column

Description

Interface

The name of the configured interface for which packets can be captured.

For information on configuring an interface, see Configuring network interfaces.

Filter Criteria

The values used to filter the packet.

# Packets

The number of packets.

Maximum Packet Count

The maximum number of packets that can be captured on a sniffer.

Progress

The status of the packet capture process.

Actions

Allows you to start and stop the capturing process, and download the most recently captured packets.

To start capturing packets on an interface, select the Start capturing button in the Actions column for that interface. The Progress column changes to Running, and the Stop capturing and Download buttons become available in the Actions column.

To add a packet sniffer:
  1. From the Packet Capture table, click Create New.

    The Create New Sniffer pane displays.

  2. Configure the following options:

    Option

    Description

    Interface

    The interface name (non-changeable).

    Max. Packets to Save

    Enter the maximum number of packets to capture, between 1-10000. The default is 4000 packets.

    Include IPv6 Packets

    Select to include IPv6 packets when capturing packets.

    Include Non-IP Packets

    Select to include non-IP packets when capturing packets.

    Enable Filters

    You can filter the packet by Host(s), Port(s), VLAN(s), and Protocol.

  3. Click OK.

To download captured packets:
  1. In the Actions column, click Download for the interface whose captured packets you want to download.

    If no packets have been captured for that interface, click Start capturing.

  2. When prompted, save the packet file (sniffer_[interface].pcap) to your management computer.

    The file can then be opened using packet analyzer software.

To edit a packet sniffer:
  1. From the Packet Capture table, click Edit.

    The Edit Sniffer pane displays.

  2. Configure the packet sniffer options

  3. Click OK.