Packet Sniffer

Use the FortiGate packet sniffer to confirm whether packets arrive on the firewall and whether replies leave the expected interface.

Syntax

diagnose sniffer packet <interface> '<filter>' <verbosity> <count> <timestamp>

Common defaults:

diagnose sniffer packet any 'host 203.0.113.10' 4 0 a

Useful filters

Host traffic:

diagnose sniffer packet any 'host 203.0.113.10' 4 0 a

HTTPS traffic:

diagnose sniffer packet any 'host 203.0.113.10 and port 443' 4 0 a

ICMP:

diagnose sniffer packet any 'icmp and host 203.0.113.10' 4 0 a

IKE and NAT-T:

diagnose sniffer packet any 'host 203.0.113.10 and (port 500 or port 4500)' 4 0 a

DNS:

diagnose sniffer packet any 'port 53' 4 0 a

Verbosity

  • 3 shows packet headers.
  • 4 shows interface names and packet headers.
  • 6 shows packet headers and payload.

Capture to a file

For longer investigations, capture from the GUI or use an external span/packet capture point where possible. CLI sniffer output is best for quick validation.