Small Unit GUI PCAP How To

So a lot of people that have smaller units have noticed in the latest versions (5.4+) that the PCAP link is now gone. Well, this video will show you how to get to that page so that you can carry out PCAPs from the GUI. We know that not everyone is as good at the CLI interface as they would like to be and this is a good shortcut to help those in need when they are troubleshooting their FortiGate.


Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

This entry was posted in FortiGate, FortinetGURU Videos, How To, Tips and Tricks on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

13 thoughts on “Small Unit GUI PCAP How To

    1. Mike Post author

      Interesting. Will load 5.4.7 on my FWF61E and see if it works. Would hate for them to remove it completely from the later builds.

      Reply
    2. Nicholas

      Hi Augustas,
      check if your Fortigate unit has an integrated HDD,i guess that having the HDD is a precondition for packet capture to work.

      Reply
      1. Mike Post author

        Yeah, otherwise you have to output via CLI and hope the buffer can keep up (bigger environments will lose packets once it overruns the buffer which can cause you to lose important information)

        Reply
  1. Reuben

    I just found this site (fortinetguru.com) and loving it too! Keep up the work Mike!
    I have a FW80CM unit running 5.6.3 and I get the 403 error code “Access denied” as mentioned above.
    Any suggestions?

    Reply
    1. Mike Post author

      Reuben,
      They yanked it on the later versions of code. Of course, they re-add it on the 6.0 firmware! (with the link and all)

      Reply
        1. Mike Post author

          The diskless ones have no where to store the pcaps. It doesn’t work or show at all on them.

          Reply
          1. flo

            Soooo what is the solution now? Should I buy an ssd and install it myself? or is there really no way to block/reserve some small amount of RAM and when that fills up just stop capturing. Or just post an warning message before?
            pcap was hidden but still available on our 3960E with 5.6.3 but no longer on 6.0.1

  2. Shane

    I just upgraded a 60E to 6.0.5 and the Packet Capture option appears in the GUI and works properly. I have seen it come and go through various firmware revisions. It initially worked in 5.4.4 but resulted in the 403 error in 5.4.6. I upgraded from 5.4.6 to 6.0.5 using the recommended upgrade path and confirmed that it returned in 6.0.5.

    Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.