How to get a circular packet capture (pcap) on a Edge SWG (ProxySG)
search cancel

How to get a circular packet capture (pcap) on a Edge SWG (ProxySG)

book

Article ID: 166431

calendar_today

Updated On:

Products

ProxySG Software - SGOS

Issue/Introduction

In some troubleshooting situation there is a need of constant packet capture that would not be stopped by packet capture size limit.

Edge SWG allows to start packet capture for "last" packets or kilobytes.

Such packet capture will be running until manually stopped.

Resolution

  • Go to Management Console > Maintenance tab > Service Information > Packet Captures
  • Select "Capture last X matching Kbytes". Enter 102400 for X's value (for example)
  • Check Include X K Bytes in core image. Enter 102400 for X's value (for example)
  • Click Start Capture


    *Note: The device may return an error after clicking 'Start Capture' due to exceeding the maximum acceptable value of K bytes. If this happens, please enter the maximum amount specified in the error instead of the value of '102400' as shown above.