To capture and send the files to the SCP server:
For a standalone Sensor, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Packet Capturing → Capture Now.
For Sensors in a stack, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <Stackname-node id> → Troubleshooting → Packet Capturing → Capture Now.
For member Sensors in a cluster, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <MemberSensorname-node id> → Troubleshooting → Packet Capturing → Capture Now.
From the Send Captured Packets To drop-down list, select An SCP Server.
Enter the SCP Server credentials, SCP Server IP (IPv4 or IPv6), SCP Server User Name and SCP Server Password.
Type the maximum file size in the Maximum Capture Size (MB) field.
Note
The maximum file size can be configured up to the maximum value of Sensor defined limits.
Click Test Connection.
The Test Connection operation establishes a connection between the Sensor and the SCP server, and creates a test file. This is to verify whether the server is reachable and the files can be written.
Note
The Test Connection operation can fail due to MACs and Ciphers mismatch between the Sensor and SCP server.
Configure the Capture Rules.
Note
If you are configuring for a Sensor from a stack of NS9500 Sensors, you cannot configure rules at an interface level. You have to configure to All interface.
Click Save to save the capture settings.
Click Start.
When the maximum file size is reached, the Sensor uploads the captured file to the Manager.
To stop the packet capture session, before the configured maximum file size, click Stop. The Sensor sends the captured file to the SCP server.
Click Cancel. The Sensor stops the capture and deletes the captured file.
Note
If file upload has started, then it cannot be canceled.