Thursday, February 5, 2015

diag debug flow from a fortigate ( local vrs interface )

Diag debug flow is the #1 trouble-shooting tool that should always be deployed from a fortigate. In this example,  I will show you how to determine if your diag debug flow caught packets that where generated locally from the unit

1st a simple filter

Now here's a  trace where packets crossed a inside to outside interface

Now here's a trace where the packets where generated locally ( in my a case a ping from the FGT100D device )

NOTE  Do you happen to notice the "from local" 

So yes diagnostic debug flow will show you any and all packets regardless if it crossed interfaces or are locally generated.

To learn more revisit one of my earlier threads.

Ken Felix
NSE ( Network Security Expert) and Route/Switching Engineer.
kfelix  -----a----t---- socpuppets ---dot---com

     ^      ^
=(  @  @ )=
        /  \

No comments:

Post a Comment