@dkzndkqh
See my lab example...IMPORTANT to point out, see how last flag shows Oe, meaning outbound and encrypted.
Andy
[Expert@R82:0]# fw monitor -e "accept port(18234);"
PPAK 0: Get before set operation succeeded of fwmonitor_kiss_enable
PPAK 0: Get before set operation succeeded of fwmonitor_debug_filter_off
PPAK 0: Get before set operation succeeded of fwmonitorfreebufs
************************************************************** NOTE **************************************************************
*** Using "-e" filter will not monitor accelerated traffic. To monitor and filter accelerated traffic please use the "-F" filter ***
************************************************************************************************************************************
FW monitor will record only ip & transport layers in a packet
For capturing the whole packet please do -w
PPAK 0: Get before set operation succeeded of fwmonitor_ppak_all_position
monitor: getting filter (from command line)
monitor: compiling
monitorfilter:
Compiled OK.
monitor: loading
monitor: monitoring (control-C to stop)
PPAK 0: Get before set operation succeeded of fwmonitormaxpacket
PPAK 0: Get before set operation succeeded of fwmonitormask
PPAK 0: Get before set operation succeeded of fwmonitorallocbufs
PPAK 0: Get before set operation succeeded of printuuid
[vs_0][fw_1] eth0:i[40]: 172.17.10.1 -> 172.16.10.253 (UDP) len=40 id=1
UDP: 18534 -> 18234
[vs_0][fw_1] eth0:I[40]: 172.17.10.1 -> 172.16.10.253 (UDP) len=40 id=1
UDP: 18534 -> 18234
[vs_0][fw_1] eth0:o[40]: 172.16.10.253 -> 172.17.10.1 (UDP) len=40 id=1
UDP: 18234 -> 18534
[vs_0][fw_1] eth0:O[40]: 172.16.10.253 -> 172.17.10.1 (UDP) len=40 id=1
UDP: 18234 -> 18534
[vs_0][fw_1] eth0:Oe[40]: 172.16.10.253 -> 172.17.10.1 (UDP) len=40 id=1
UDP: 18234 -> 18534
[vs_0][fw_1] eth0:i[40]: 172.17.10.1 -> 172.16.10.253 (UDP) len=40 id=1
UDP: 18535 -> 18234
[vs_0][fw_1] eth0:I[40]: 172.17.10.1 -> 172.16.10.253 (UDP) len=40 id=1
UDP: 18535 -> 18234
[vs_0][fw_1] eth0:o[40]: 172.16.10.253 -> 172.17.10.1 (UDP) len=40 id=1
UDP: 18234 -> 18535
[vs_0][fw_1] eth0:O[40]: 172.16.10.253 -> 172.17.10.1 (UDP) len=40 id=1
UDP: 18234 -> 18535
[vs_0][fw_1] eth0:Oe[40]: 172.16.10.253 -> 172.17.10.1 (UDP) len=40 id=1
UDP: 18234 -> 18535
^C monitor: caught sig 2
monitor: unloading
PPAK 0: Get before set operation succeeded of fwmonitor_kiss_enable
PPAK 0: Get before set operation succeeded of fwmonitor_debug_filter_off
PPAK 0: Get before set operation succeeded of fwmonitorfreebufs
[Expert@R82:0]#
Best,
Andy
"Have a great day and if its not, change it"