03.05.2015 Views

What is Packet Capture? - SonicWALL

What is Packet Capture? - SonicWALL

What is Packet Capture? - SonicWALL

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring <strong>Packet</strong> <strong>Capture</strong><br />

Figure 11<br />

Advanced Settings Window<br />

Step 4<br />

Step 5<br />

Step 6<br />

Step 7<br />

Step 8<br />

To capture packets generated by the <strong>SonicWALL</strong> appliance, select the <strong>Capture</strong> Firewall Generated<br />

<strong>Packet</strong>s checkbox.<br />

Even when interfaces specified in the capture filters do not match, th<strong>is</strong> option ensures that packets<br />

generated by the <strong>SonicWALL</strong> appliance are captured. Th<strong>is</strong> includes packets generated by HTTP(S), L2TP,<br />

DHCP servers, PPP, PPPOE, and routing protocols. <strong>Capture</strong>d packets are marked with ‘s’ in the incoming<br />

interface area when they are from the system stack. Otherw<strong>is</strong>e, the incoming interface <strong>is</strong> not specified.<br />

To capture intermediate packets generated by the <strong>SonicWALL</strong> appliance, select the <strong>Capture</strong> Intermediate<br />

<strong>Packet</strong>s checkbox.<br />

Intermediate packets include packets generated as a result of fragmentation or reassembly, intermediate<br />

encrypted packets, IP helper generated packets, and replicated multicast packets.<br />

To exclude encrypted management or syslog traffic to or from GMS, select the Exclude encrypted GMS<br />

traffic checkbox.<br />

Th<strong>is</strong> setting only affects encrypted traffic within a configured primary or secondary GMS tunnel. GMS<br />

management traffic <strong>is</strong> not excluded if it <strong>is</strong> sent via a separate tunnel.<br />

To exclude management traffic, select the Exclude Management Traffic checkbox and select one or more<br />

checkboxes for HTTP/HTTPS, SNMP, or SSH.<br />

If management traffic <strong>is</strong> sent via a tunnel, the packets are not excluded.<br />

To exclude syslog traffic to a server, select the Exclude Syslog Traffic to checkbox and select one or more<br />

checkboxes for Syslog Servers or GMS Server.<br />

If syslog traffic <strong>is</strong> sent via a tunnel, the packets are not excluded.<br />

Restarting FTP Logging<br />

If automatic FTP logging <strong>is</strong> off, either because of a failed connection or simply d<strong>is</strong>abled, you can restart it<br />

in Configure > Logging.<br />

Step 1<br />

Navigate to the <strong>Packet</strong> <strong>Capture</strong> page in the UI.<br />

SonicOS Enhanced <strong>Packet</strong> <strong>Capture</strong><br />

17

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!