SonicOS 7.1 Objects

Capturing Packets Related to a Policy

Make sure that at least one rule is configured from the below list:

  • An App Rules policy with the Packet Monitor as an Action Object.
  • An Access Rules policy that uses Packet Monitor.

To control the Packet Monitor action to capture only the packets related to your policy

  1. Navigate to MONITOR | Tools & Monitors > Packet Monitor > General.

  2. Click Monitor Filter tab.

  3. Select Enable Filter based on the firewall/app rule to filter the traffic based on the app rule or access rule policy.
  4. Click Save.
  5. Navigate to Capture Packets tab and click Start Capture.

    Packets are not captured until some traffic triggers an App Rules policy (or an Access Rule). You can see the Alert message in the MONITOR | Logs > System Event page when the policy is triggered.

  6. Click Stop Capture after you have captured the desired packets.

    You can Export the capture into different formats and look at it in a browser.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden