- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-07-2018 01:58 PM
You can merge the PCAPs once you've finished collectiong them, however the stage is what the firewall is actually capturing so it isn't able to take a full capture of everything.
* Drops: Records packets that are dropped due to an error.
* Firewall: Captures when the device is processing packets.
* Receive: Packets that are recieved by the device.
* Transmit: Packets sent from the source.
If you utilize WireShark you can actually merge all of these chronologically to essentially get what you are looking for in one large file. To do so simply open one of the PCAPs and select File > Merge select the other PCAP and then select whether you want to Prepend, Append, or Merge Chronologically.