Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
barryh
New Contributor

FW-100E no "packet capture"

Hello, I have a 100E (5.4.4) and there is no  "packet capture" under "Network", now i cant find if this supported or not, i know in the past fortigate disabled this feature for small models in relation to process power, but a 100E isn't small or slow in my opinion.

 

Can someone point me to the right document? Sorry, i really have to work on my search skills.

 

Thanks in advance

1 Solution
Jim_FH
New Contributor III

We ran into this with the 200E.

 

It's due to the boxes not having local disk storage.

View solution in original post

5 REPLIES 5
Jim_FH
New Contributor III

We ran into this with the 200E.

 

It's due to the boxes not having local disk storage.

Alby23
Contributor II

You cannot use packet capture via GUI if you have a FortiGate without hard drive (so you have to use a 101, 201 and so on).

 

You can use the 'diagnose sniffer packet' and the perl script in order to convert the output in a pcap file (like the good old days).

Alex_talmage
New Contributor

I was looking for this today myself on my 800D, as though I like the diag sniffer CLI, it wanted to dig a little deeper in a pcap file with Wireshark. I believe, though cannot confirm, that the packet capture needs a log disk configured. We are currently using our disk for wan optimization caching, so it would add up. Check that your 100E has a log disk configured:

 

get sys status and check the "Log hard disk" entry. If it says "Not available" then either the 100E doesn't come with a log disk, or its being used for something else.

 

Next run

config system global

show

 

See if set disk-usage wanopt exists. Or try running set disk-usage logging and see if this updates in get sys status.

MikePruett

Depending on the OS version it was straight up removed. (You can still navigate to it if you remember the URL structure though).

 

You do need a disk to record it though.

Mike Pruett Fortinet GURU | Fortinet Training Videos
barryh

It doesn't have a disk, so my question is answered. Thanks a lot guys!

Labels
Top Kudoed Authors