Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Packet Capture

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 2 Posters 604 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rehstp
      last edited by

      I know how to setup a packet capture, but is there a way to set it up to capture after an alert for so long?

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        I don't think you can.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • R
          rehstp
          last edited by

          By chance do you know if there is anything out there that can do this?

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by

            Nope.

            I'd use port mirroring on the switch that the router connects to, connect a laptop to the mirror port, leave a capture running on Wireshark and create a new file after X Gb

            It's not ideal.

            What "alert" are you trying to capture?

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • R
              rehstp
              last edited by

              For alerts im Just trying to get more information on what is happening.  Currently I have this system setup with 2 ports one for management and another for traffic.  The traffic port has no ip on it and at the switch I have all external traffic coming in and out mirrored to it.  I could run a constant capture on this interface, but it will fill up the box in no time.  Im just trying to find something out there to pull a full pcap upon a triggered alert.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.