Fortinet white logo
Fortinet white logo

CLI Reference

config firewall on-demand-sniffer

config firewall on-demand-sniffer

Configure on-demand packet sniffer.

config firewall on-demand-sniffer
    Description: Configure on-demand packet sniffer.
    edit <name>
        set interface <name1>, <name2>, ...
        set max-packet-count {integer}
        set hosts <host1>, <host2>, ...
        set hostnames <hostname1>, <hostname2>, ...
        set snapshot-length {integer}
        set ports <port1>, <port2>, ...
        set protocols <protocol1>, <protocol2>, ...
        set non-ip-packet [enable|disable]
        set advanced-filter {var-string}
    next
end

config firewall on-demand-sniffer

Parameter

Description

Type

Size

Default

name

On-demand packet sniffer name.

string

Maximum length: 35

interface <name>

Interface names that on-demand packet sniffer will take place.

Interface name.

string

Maximum length: 79

max-packet-count

Maximum number of packets to capture per on-demand packet sniffer.

integer

Minimum value: 1 Maximum value: 20000

0

hosts <host>

IPv4 or IPv6 hosts to filter in this traffic sniffer.

IPv4 or IPv6 host.

string

Maximum length: 255

hostnames <hostname>

Hostnames to filter in this traffic sniffer.

Hostname.

string

Maximum length: 255

snapshot-length

Maximum number of bytes to capture per packet.

integer

Minimum value: 1 Maximum value: 262144

1600

ports <port>

Ports to filter for in this traffic sniffer.

Port to filter in this traffic sniffer.

integer

Minimum value: 1 Maximum value: 65536

protocols <protocol>

Protocols to filter in this traffic sniffer.

Integer value for the protocol type as defined by IANA (0 - 255).

integer

Minimum value: 0 Maximum value: 255

non-ip-packet

Include non-IP packets.

option

-

disable

Option

Description

enable

Enable non-IP packets to be included capture.

disable

Disable non-IP packets to be included in capture.

advanced-filter

Advanced freeform filter that will be used over existing filter settings if set. Can only be used by super admin.

var-string

Maximum length: 255

config firewall on-demand-sniffer

config firewall on-demand-sniffer

Configure on-demand packet sniffer.

config firewall on-demand-sniffer
    Description: Configure on-demand packet sniffer.
    edit <name>
        set interface <name1>, <name2>, ...
        set max-packet-count {integer}
        set hosts <host1>, <host2>, ...
        set hostnames <hostname1>, <hostname2>, ...
        set snapshot-length {integer}
        set ports <port1>, <port2>, ...
        set protocols <protocol1>, <protocol2>, ...
        set non-ip-packet [enable|disable]
        set advanced-filter {var-string}
    next
end

config firewall on-demand-sniffer

Parameter

Description

Type

Size

Default

name

On-demand packet sniffer name.

string

Maximum length: 35

interface <name>

Interface names that on-demand packet sniffer will take place.

Interface name.

string

Maximum length: 79

max-packet-count

Maximum number of packets to capture per on-demand packet sniffer.

integer

Minimum value: 1 Maximum value: 20000

0

hosts <host>

IPv4 or IPv6 hosts to filter in this traffic sniffer.

IPv4 or IPv6 host.

string

Maximum length: 255

hostnames <hostname>

Hostnames to filter in this traffic sniffer.

Hostname.

string

Maximum length: 255

snapshot-length

Maximum number of bytes to capture per packet.

integer

Minimum value: 1 Maximum value: 262144

1600

ports <port>

Ports to filter for in this traffic sniffer.

Port to filter in this traffic sniffer.

integer

Minimum value: 1 Maximum value: 65536

protocols <protocol>

Protocols to filter in this traffic sniffer.

Integer value for the protocol type as defined by IANA (0 - 255).

integer

Minimum value: 0 Maximum value: 255

non-ip-packet

Include non-IP packets.

option

-

disable

Option

Description

enable

Enable non-IP packets to be included capture.

disable

Disable non-IP packets to be included in capture.

advanced-filter

Advanced freeform filter that will be used over existing filter settings if set. Can only be used by super admin.

var-string

Maximum length: 255