System_systemPacketCaptureView
Dashboard > Packet Monitor
Note: For increased convenience and accessibility, the Packet Monitor page can be accessed either from Dashboard > Packet Monitor or System > Packet Monitor. The page is identical regardless of which tab it is accessed through. For detailed overview and configuration information on Packet Monitor, refer to the System > Packet Monitor.
Using Packet Monitor and Packet Mirror
In addition to the Configure button, the top of the Dashboard > Packet Monitor page provides several buttons for general control of the packet monitor feature and display. These include the following:
The Dashboard > Packet Monitor page is shown below:
For an explanation of the status indicators near the top of the page, see Understanding Status Indicators.
The other buttons and displays on this page are described in the following sections:
Starting and Stopping Packet Capture
You can start a packet capture that uses default settings without configuring specific criteria for packet capture, display, FTP export, and other settings. If you start a default packet capture, the Dell SonicWALL security appliance will capture all packets except those for internal communication, and will stop when the buffer is full or when you click Stop Capture.
You can view the captured packets in the Captured Packets, Packet Detail, and Hex Dump sections of the screen. See Viewing Captured Packets .
Starting and Stopping Packet Mirror
You can start packet mirroring that uses your configured mirror settings by clicking Start Mirror. It is not necessary to first configure specific criteria for display, logging, FTP export, and other settings. Packet mirroring stops when you click Stop Mirror.
Viewing Captured Packets
The Dashboard > Packet Monitor page provides three windows to display different views of captured packets. The following sections describe the viewing windows:
About the Captured Packets Window
The Captured Packets window displays the following statistics about each packet:
i
Interface
hc
Hardware based encryption or decryption
sc
Software based encryption or decryption
m
Multicast
r
Packet reassembly
s
System stack
ip
IP helper
f
Fragmentation
The status field shows the state of the packet with respect to the firewall. A packet can be dropped, generated, consumed or forwarded by the Dell SonicWALL security appliance. You can position the mouse pointer over dropped or consumed packets to show the following information.
Dropped
Module-ID = <integer>
Value for the protocol subsystem ID
Drop-code = <integer>
Reason for dropping the packet
Reference-ID: <code>
SonicWALL-specific data
Consumed
Module-ID = <integer>
Value for the protocol subsystem ID
About the Packet Detail Window
When you click on a packet in the Captured Packets window, the packet header fields are displayed in the Packet Detail window. The display will vary depending on the type of packet that you select.
About the Hex Dump Window
When you click on a packet in the Captured Packets window, the packet data is displayed in hexadecimal and ASCII format in the Hex Dump window. The hex format is shown on the left side of the window, with the corresponding ASCII characters displayed to the right for each line. When the hex value is zero, the ASCII value is displayed as a dot.
Dashboard > Log Monitor
Note: For increased convenience and accessibility, the Log Monitor page can be accessed either from Dashboard > Log Monitor or Log > View. The two pages provide identical functionality. For information on using Log Monitor, see Log > View.