Parsing Packets in a Packet Capture File

Packet parsing can be performed on all packet capture files to obtain details on the packets.

Prerequisites

A packet capture task has been created and enabled.

Procedure

  1. Choose Defense > Policy Settings > Packet Capture.
  2. Click the Packet Capture File tab.
  3. Click of a packet capture file in the Operation column to parse captured packets.
  4. On the Packet Parsing page, you can view details on each packet, including the sending time, source IP address, destination IP address, protocol type of the packet.
  5. Click each packet parsing record, the details are displayed in the group boxes in the middle or below.

  6. Select the fingerprint content and click Extract Fingerprint.
  7. In Add Fingerprint, define a filter name and click Add the Fingerprint.
  8. Click OK.
  9. Click Close. Return to the Packet Capture File page.
  10. Choose Defense > Policy Settings > Filter > Filter. You can view the filter generated when adding a fingerprint. You need to associate the filter to a Zone and deploy it to the device to make the filter take effect.

Copyright © Huawei Technologies Co., Ltd.