Fortinet black logo

Administration Guide

Packet capture

Packet capture

Packets can be captured on configured interfaces by going to System > Network > Packet Capture.

The following information is available:

Interface

The name of the configured interface for which packets can be captured.

For information on configuring an interface, see Configuring network interfaces.

Filter Criteria The values used to filter the packet.

# Packets

The number of packets.

Maximum Packet Count The maximum number of packets that can be captured on a sniffer.
Progress The status of the packet capture process.

Actions

Allows you to start and stop the capturing process, and download the most recently captured packets.

To start capturing packets on an interface, select the Start capturing button in the Actions column for that interface. The Progress column changes to Running, and the Stop capturing and Download buttons become available in the Actions column.

To add a packet sniffer:
  1. From the Packet Capture table, click Create New in the toolbar. The Create New Sniffer pane opens.
  2. Configure the following options:

    Interface The interface name (non-changeable).
    Max. Packets to Save Enter the maximum number of packets to capture, between 1-10000. The default is 4000 packets.
    Include IPv6 Packets Select to include IPv6 packets when capturing packets.
    Include Non-IP Packets Select to include non-IP packets when capturing packets.
    Enable Filters

    You can filter the packet by Host(s), Port(s), VLAN(s), and Protocol.

  3. Click OK.
To download captured packets:
  1. In the Actions column, click the Download button for the interface whose captured packets you want to download.

    If no packets have been captured for that interface, click the Start capturing button.

  2. When prompted, save the packet file (sniffer_[interface].pcap) to your management computer.

    The file can then be opened using packet analyzer software.

To edit a packet sniffer:
  1. From the Packet Capture table, click Edit in the toolbar. The Edit Sniffer pane opens.
  2. Configure the packet sniffer options
  3. Click OK.

Packet capture

Packets can be captured on configured interfaces by going to System > Network > Packet Capture.

The following information is available:

Interface

The name of the configured interface for which packets can be captured.

For information on configuring an interface, see Configuring network interfaces.

Filter Criteria The values used to filter the packet.

# Packets

The number of packets.

Maximum Packet Count The maximum number of packets that can be captured on a sniffer.
Progress The status of the packet capture process.

Actions

Allows you to start and stop the capturing process, and download the most recently captured packets.

To start capturing packets on an interface, select the Start capturing button in the Actions column for that interface. The Progress column changes to Running, and the Stop capturing and Download buttons become available in the Actions column.

To add a packet sniffer:
  1. From the Packet Capture table, click Create New in the toolbar. The Create New Sniffer pane opens.
  2. Configure the following options:

    Interface The interface name (non-changeable).
    Max. Packets to Save Enter the maximum number of packets to capture, between 1-10000. The default is 4000 packets.
    Include IPv6 Packets Select to include IPv6 packets when capturing packets.
    Include Non-IP Packets Select to include non-IP packets when capturing packets.
    Enable Filters

    You can filter the packet by Host(s), Port(s), VLAN(s), and Protocol.

  3. Click OK.
To download captured packets:
  1. In the Actions column, click the Download button for the interface whose captured packets you want to download.

    If no packets have been captured for that interface, click the Start capturing button.

  2. When prompted, save the packet file (sniffer_[interface].pcap) to your management computer.

    The file can then be opened using packet analyzer software.

To edit a packet sniffer:
  1. From the Packet Capture table, click Edit in the toolbar. The Edit Sniffer pane opens.
  2. Configure the packet sniffer options
  3. Click OK.