What is Packet Capture? - SonicWALL
What is Packet Capture? - SonicWALL
What is Packet Capture? - SonicWALL
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Configuring <strong>Packet</strong> <strong>Capture</strong><br />
Figure 11<br />
Advanced Settings Window<br />
Step 4<br />
Step 5<br />
Step 6<br />
Step 7<br />
Step 8<br />
To capture packets generated by the <strong>SonicWALL</strong> appliance, select the <strong>Capture</strong> Firewall Generated<br />
<strong>Packet</strong>s checkbox.<br />
Even when interfaces specified in the capture filters do not match, th<strong>is</strong> option ensures that packets<br />
generated by the <strong>SonicWALL</strong> appliance are captured. Th<strong>is</strong> includes packets generated by HTTP(S), L2TP,<br />
DHCP servers, PPP, PPPOE, and routing protocols. <strong>Capture</strong>d packets are marked with ‘s’ in the incoming<br />
interface area when they are from the system stack. Otherw<strong>is</strong>e, the incoming interface <strong>is</strong> not specified.<br />
To capture intermediate packets generated by the <strong>SonicWALL</strong> appliance, select the <strong>Capture</strong> Intermediate<br />
<strong>Packet</strong>s checkbox.<br />
Intermediate packets include packets generated as a result of fragmentation or reassembly, intermediate<br />
encrypted packets, IP helper generated packets, and replicated multicast packets.<br />
To exclude encrypted management or syslog traffic to or from GMS, select the Exclude encrypted GMS<br />
traffic checkbox.<br />
Th<strong>is</strong> setting only affects encrypted traffic within a configured primary or secondary GMS tunnel. GMS<br />
management traffic <strong>is</strong> not excluded if it <strong>is</strong> sent via a separate tunnel.<br />
To exclude management traffic, select the Exclude Management Traffic checkbox and select one or more<br />
checkboxes for HTTP/HTTPS, SNMP, or SSH.<br />
If management traffic <strong>is</strong> sent via a tunnel, the packets are not excluded.<br />
To exclude syslog traffic to a server, select the Exclude Syslog Traffic to checkbox and select one or more<br />
checkboxes for Syslog Servers or GMS Server.<br />
If syslog traffic <strong>is</strong> sent via a tunnel, the packets are not excluded.<br />
Restarting FTP Logging<br />
If automatic FTP logging <strong>is</strong> off, either because of a failed connection or simply d<strong>is</strong>abled, you can restart it<br />
in Configure > Logging.<br />
Step 1<br />
Navigate to the <strong>Packet</strong> <strong>Capture</strong> page in the UI.<br />
SonicOS Enhanced <strong>Packet</strong> <strong>Capture</strong><br />
17