packet-capture
Syntax
Hierarchy Level
Release Information
Statement introduced in Junos OS Release 20.2R1.
Description
Specify packet capture options to capture unknown application traffic.
You can use the packet capture of unknown applications functionality
to gather more details about an unknown application on your security
device. Once you’ve configured packet capture options on your
security device, the unknown application traffic is gathered and stored
on the device in a packet capture file (.pcap
) at /var/log/pcap/
location.
Options
Default: 1% of available data in shared memory
Range: 0% through 5% of available data in shared memory
Default: 1 MB (for cSRX)
Range: 0 through 5 MB
Default: 1440 minutes (24 hours).
Range: 1 through 525,600 seconds
Default: 4
Range: 1 through 1000
If you are setting the packet capture at the security policy level, the packet capture concludes only after the final policy is applied even if the configured limit is reached.
Limitation—Jumbo frames can have up to 1500 bytes of the payload saved in the capture file.
Default: 6000 bytes
Range: 40 through 1,073,741,824
Default: 25
Range: 1 through 2500
Default: 10 packets
Range: 1 through 1000
Sessions that are closed before the application identification or classification completes.
Sessions that are not getting classified even whn they reach the maximum packet capture limit.
If you do not configure this option, by default, the system captures packets for inconclusive sessions.
Default: 50 MB
Range: 1,048,576 through 4,294,967,295 bytes
Required Privilege Level
system