Capturing packets from a sniffer VLAN in a FortiLink setup
This cookbook article documents how to capture packets on a VLAN that is being used as the network sniffer (also known as the packet analyzer) and then send the packets to a remote destination.
To capture packets (mirror traffic) on the FortiSwitch fabric, you need to decide what traffic you want to examine. The traffic can be specific switch ports, MAC addresses , or IP addresses. Then you can decide where to send the packet capture (mirrored traffic) to. The destination can be the FortiGate unit, where you can use the local FortiGate packet capture facility, or the destination can be somewhere else in the network (such as across the network through the FortiGate unit or a device directly connected to the FortiSwitch fabric).