- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-05-2012 08:21 AM
Hi...
I’d like to a packet dump about incomplete, not-applicable, insufficient-data.
I tried to set a packet dump command like below.
Set application dump on application incomplete
Set application dump on application not-applicable.
Set application dump on application insufficient-data.
But, I can’t see any packet capture related to these applications from traffic log in Monitor TAB.
Is it impossible to capture of these applications on PAN device??
If it is possible, how can I capture these applications capture on PAN device?
Thanks,
Eugene.
04-05-2012 08:53 AM
Hi Eugene,
a datastream is known as incomplete, not-applicable or with insufficient-data, if the session will be blocked by rule or does not find a existing service on the destination system. So you can see only one "tcp syn" packet in the dump (for instance). Imho this makes no sense.
greetings
Manfred
04-05-2012 05:47 PM
Hi mhuels
Thanks for your opinion.
and of course I agree about your mention.
Nevertheless, I need to capture these application to verify packet.
Actually, customer believes that incomplete and other packet lead to network connection problem between specific client and server.
Therefore I have to show that incomplete packet was not interrupted between the client and server connection.
as a evidence, i am going to show these packets.
Please teach me, if you know how to capture a dump related to these application.
Thanks,
Eugene.
04-10-2012 02:41 PM
You can create packet captures using the WebGUI as of version 4.0x and bove.
Monitor>>Packet Capture>>
You'd need to enable the filter (for the specific traffic you want to monitor) - "Manage Filter" and to then enable the captures. The packets can be captured at each of the 4 stages: transmit /receive/ firewall/ and drop.
YOU MUST ENABLE THE CAPTURE AFTER ENABLING THE FILTER otherwise the device may start capturing all the traffic through the device and that can lead to device crashes.
PLEASE ONLY SET CAPTURE ON AFTER FILTER HAS BEEN SET TO ON and disable the capture as soon as you done so as to not keep capturing.
Hope this helps
05-07-2012 03:45 PM
I have a customer that is also trying to capture packets for incomplete, not-applicable, and insufficient-data. The filters you mentioned do not allow you to capture based on application. Is there another way to capture this data?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!