User's Manual

System > Packet Capture
116
SonicOS Enhanced 4.0 Administrator Guide
SonicOS Enhanced adds one of four possible packet status values to each captured
packet: forwarded, generated, consumed, and dropped. You can select one or more of
these status values to match when displaying packets. The status value shows the state of
the packet with respect to the firewall, as follows:
Forwarded - The packet arrived on one interface and the SonicWALL appliance sent it
out on another interface.
Generated - The SonicWALL appliance created the packet during the process of
encryption or decryption, fragmentation or reassembly, or as a result of certain
protocols.
Consumed - The packet was destined for the SonicWALL appliance.
Dropped - The SonicWALL appliance did nothing further with the packet. The firewall
might have identified the packet as malformed, malicious, on the deny list, or not on the
allow list.
Note If a field is left blank, no filtering is done on that field. Packets are displayed without regard
to the value contained in that field of their headers.
Step 1 Navigate to the Packet Capture page in the UI. See “Accessing Packet Capture in the UI” on
page 108.
Step 2 Under Packet Capture, click Configure.
Step 3 In the Packet Capture Configuration window, click the Display Filter tab.