欢迎来到天天文库
浏览记录
ID:47280603
大小:16.19 KB
页数:3页
时间:2019-09-02
《Fortigate防火墙抓包命令》由会员上传分享,免费在线阅读,更多相关内容在应用文档-天天文库。
1、Fortigate防火墙抓包命令在Fortigate防火墙上Troubleshooting,绝大多数情况下,用好DiagnoseSniffer和Diagnosedebug这两个命令就能解决很多问题。一般来说,Troubleshooting时,先用Sniffer命令查看数据包到底有没有到达防火墙,然后用Debug命令来查看数据包达到防火墙后是怎样的处理流程。Sniffer命令格式:Fortigate#diagnosesnifferpacket''举例:抓包IP地址10.2
2、.22.21与202.103.24.68之间所有的DNS通信FG200D3915807028#diagnosesnifferpacketany'port53andhost10.2.22.21and202.103.24.68'输出结果示例:interfaces=[any]filters=[port53andhost10.2.22.21and202.103.24.68]23.01556310.2.22.21.53751->202.103.24.68.53:udp4823.043507202.103.24.68.53->1
3、0.2.22.21.53751:udp6423.04474310.2.22.21.53752->202.103.24.68.53:udp48Sniffer命令支持几种不同详尽程度的输出方式,在输入完抓包命令之后打个问号可以显示输出详尽程度的选项FG200D3915807028#diagnosesnifferpacketany'port53andhost10.2.22.21and202.103.24.68'?1:printheaderofpackets2:printheaderanddatafromi
4、pofpackets3:printheaderanddatafromethernetofpackets(ifavailable)4:printheaderofpacketswithinterfacename5:printheaderanddatafromipofpacketswithinterfacename6:printheaderanddatafromethernetofpackets(ifavailable)withintfname或者直接在抓包命令后加个“空格+数字1-6",例如FG200D391580702
5、8#diagnosesnifferpacketany'port53andhost10.2.22.21and202.103.24.68'6输出的结果示例如下:interfaces=[any]filters=[port53andhost10.2.22.21and202.103.24.68]21.327456OA-Zonein10.2.22.21.61158->202.103.24.68.53:udp470x000000000000000118c58a1b3cdc08004500..........<...E.0x0010
6、004b05d000007f1133100a021615ca67.K......3......g0x00201844eee600350037daef000301000001.D...5.7........0x00300000000000000377777704736f687503.......www.sohu.0x0040636f6d0c6d6963726f7061747465726ecom.0x005003636f6d0000010001.....21.349692OA-Zoneout202.103.24.68.5
7、3->10.2.22.21.61158:udp630x0000000000000000906cac02557908004500.......l..Uy..E.0x0010005b000040003b113cd0ca6718440a02.[..@.;.<..g.D..0x002016150035eee6004782d7000381800001...5...G........0x00300001000000000377777704736f687503.......www.sohu.0x0040636f6d0c6d6963
8、726f7061747465726ecom0x005003636f6d0000010001c00c0001000100............0x006000025800047150431c..X..qPC.21.350943OA-Zonein10.2.22.21.61159->202.103.24.68.53:udp470x000000000
此文档下载收益归作者所有