Skip to content

Display filter

You can restrict the packet capturing to specific types of packets. Display filter allows you to set additional filtering conditions such as the type of interface, ether type, source IP address, and destination IP address.

  1. Go to Diagnostics > Packet capture and click Display filter.
  2. Enter the details as follows:

    Option Description
    Interface name From the list, select the physical interface used for filtering packets logs.
    Ethernet type Select the Ethernet type: IPv4, IPv6, or ARP.
    Ethernet type is a field in an Ethernet frame. It indicates the protocol encapsulated in the Ethernet frame.
    Packet type From the list, select the packet type used for filtering packets.
    Source IP Specify the source IP address (IPv4 or IPv6).
    Source port Specify the source port number.
    Destination IP Specify the destination IP address (IPv4 or IPv6).
    Destination port Specify the destination port number.
    Reason

    Select the reason to display the filter from the available options.

    • Firewall
    • LOCAL_ACL
    • DOS_ATTACK
    • INVALID_TRAFFIC
    • INVALID_FRAGMENTED_TRAFFIC
    • ICMP_REDIRECT
    • SOURCE_ROUTED_PACKET
    • FRAGMENTED_TRAFFIC
    • APPLICATION_FILTER
    • USER_IDENTITY
    • IPS
    • MAC_FILTER
    • IPMAC_FILTER
    • IP_SPOOF
    • NEIGHBOR_POISONING
    • SSL_VPN_ACL_VIOLATION
    • VIRTUAL_HOST
    • ICMP ERROR MESSAGE
    Status

    Select the status of the filter from the available options:

    • Allowed
    • Violation
    • Consumed
    • Generated
    • Incoming
    • Forwarded
    Rule ID Specify an ID for the rule.
    User Select a user from the list of already existing users.
    Connection ID Specify a connection ID.
    Clear Click to delete the filter settings.
  3. Click Save.