You can capture incoming and outgoing packets in NS9600, NS9500, NS9x00, NS7600, NS7500, NS7x50, NS7x00, NS5x00, NS3600, NS3500, NS3200, NS3100, and Virtual IPS Sensors from the Sensor CLI. The following CLI commands are available in the Sensors that allow you to capture packets:
Note
Capturing of jumbo packet frames from the Sensor CLI is not supported in both port mode and file mode.
Note
The CLI commands mentioned are applicable only when packet capture is configured in file mode.
pktcapture intfportpktcapture intfport-pairpktcapture stack-nodepktcapturefile(Discard or upload captured packets to the Manager or SCP server based on the configuration.)
To capture packets continuously, the following CLI commands are available:
pktcapture-circular intfportpktcapture-circular intfport-pairpktcapture-circular stack-node
To debug various integration or connectivity issues on the management port, the CLI command pktcapture mgmt is available.
Note
The packet capture feature is mainly for troubleshooting purposes. Trellix recommends you enable it for a limited period with appropriate supervision.
Note
Trellix recommends that you ensure appropriate filters are applied when enabling packet capture. Otherwise, this can affect the Sensor performance.
These CLI commands allow you to capture packets from the Sensor CLI on an ad-hoc basis. The commands use the configuration in the Manager to determine if the captured packets should be sent to the Manager or to an SCP server. If you have configured the Manager to send captured packets to a SPAN port, you cannot capture packets by using these commands.
Note
If the Manager is in the process of capturing packets and at the same time you run this command from the Sensor CLI, the Sensor will display a message that a packet capture process is already running. Similarly, if you have started packet capture from the CLI, the Manager displays the packet capture Status as Running. In the Manager, you cannot stop a packet capture session that is started in the CLI and vice-versa. As a best practice, you should start and stop a packet capture session from the same place; either from the CLI or from the Manager.
For more information on the CLI commands, see IPS CLI Commands - Normal Mode .