In addition to the
Configure
button, the top of the Dashboard > Packet Monitor
page provides several buttons for general control of the packet monitor feature and display. These include the following:
|
•
|
Monitor All
– Resets current monitor filter settings and advanced page settings so that traffic on all local interfaces is monitored. A confirmation dialog box displays when you click this button.
|
|
•
|
Monitor Default
– Resets current monitor filter settings and advanced page settings to factory default settings. A confirmation dialog box displays when you click this button.
|
|
•
|
Clear
– Clears the packet monitor queue and the displayed statistics for the capture buffer, mirroring, and FTP logging. A confirmation dialog box displays when you click this button.
|
|
•
|
Refresh
– Refreshes the packet display windows on this page to show new buffer data.
|
The Dashboard > Packet Monitor page is shown below:
For an explanation of the status indicators near the top of the page, see
“Understanding Status Indicators”
.
The other buttons and displays on this page are described in the following sections:
You can start a packet capture that uses default settings without configuring specific criteria for
packet capture, display, FTP export, and other settings. If you start a default packet capture, the SonicWALL appliance will capture all packets except those for internal communication, and will stop when the buffer is full or when you click Stop Capture
.
Step 3
|
Under
Packet Monitor
, click Start Capture
.
|
You can view the captured packets in the Captured Packets, Packet Detail, and Hex Dump
sections of the screen. See “Viewing Captured Packets”
.
You can start packet mirroring that uses your configured mirror settings by clicking
Start Mirror
. It is not necessary to first configure specific criteria for display, logging, FTP export, and other settings. Packet mirroring stops when you click Stop Mirror
.
Step 2
|
Under
Packet Monitor
, click Start Mirror
to start mirroring packets according to your configured settings.
|
The
Dashboard > Packet Monitor
page provides three windows to display different views of captured packets. The following sections describe the viewing windows:
The
Captured Packets
window displays the following statistics about each packet:
The status field shows the state of the packet with respect to the firewall. A packet can be
dropped, generated, consumed or forwarded by the SonicWALL appliance. You can position the mouse pointer over dropped or consumed packets to show the following information.
When you click on a packet in the Captured Packets window, the packet header fields are
displayed in the Packet Detail window. The display will vary depending on the type of packet that you select.
When you click on a packet in the Captured Packets window, the packet data is displayed in
hexadecimal and ASCII format in the Hex Dump window. The hex format is shown on the left side of the window, with the corresponding ASCII characters displayed to the right for each line. When the hex value is zero, the ASCII value is displayed as a dot.