This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

How do you capture from firewall?

0

I have a WatchGuard XTM 505 Firewall appliance. I need to see the amount of data flow that comes in and out of the network over time to establish what kind of throughput the WAN connection demands. We are considering T1 as this is the best option available in our area. The point of this is to establish if we need two Bonded T1s or if a single T1 will work for our purposes.

Thanks, jeffp88

asked 13 Dec '12, 08:08

jeffp88's gravatar image

jeffp88
1111
accept rate: 0%


One Answer:

0

I'm not familiar with the exact model, but doesn't it have some sort of statistics module on its own you can use? Capturing/analyzing packets is something that isn't always the only option, so if you have other means of getting what you need you should.

If you need to capture packets you could do that by capturing the WAN link port on the switch it is connected to. Take a look here for ways to get the packets: http://wiki.wireshark.org/CaptureSetup/Ethernet

answered 13 Dec '12, 14:33

Jasper's gravatar image

Jasper ♦♦
23.8k551284
accept rate: 18%