For further information about using the Packet Monitor, refer to SonicOS 7 Diagnostics.
To capture decrypted messages to or from the SSO authentication agent
The packets are marked with (sso) in the ingress/egress interface field. They have dummy Ethernet, TCP, and IP headers, so some values in these fields might not be correct.
This enables decrypted SSO packets to be fed to the Packet Monitor, but any monitor filters are still applied to them.
Captured SSO messages are displayed fully decoded on the Tools > Packet Monitor page.