Packet capture: not possible for VPN interfaces
Freshman Member
Hello,
I have SSL VPN setup and is up and running. In the Diagnostics - Packet Capture I can't select corresponding interface. Why?!
Accepted Solution
-
Hi @Rösti
Currently method to capture the SSL VPN traffic is to use command "cmd traffic-capture tun0".
If you need the Diagnostics - Packet Capture to support SSL VPN in the available interface selection, please share the detailed reason with us. Thanks.
Zyxel Melen0
All Replies
-
Its just something thats not been done might be for performance reason?
But you can Packet Capture interfaces that the VPN exits.
0 -
Hi @Rösti
Currently method to capture the SSL VPN traffic is to use command "cmd traffic-capture tun0".
If you need the Diagnostics - Packet Capture to support SSL VPN in the available interface selection, please share the detailed reason with us. Thanks.
Zyxel Melen0 -
🤦♂️just avoid your windbag replies in my posts.
0 -
Hi @Zyxel_Melen,
Thanks for the hint, will use it that way.
However, why it shall be a specific reason to have it in a GUI? I would be rather interested in why it is not there, as it seems it was deliberately done so…
0 -
Hi @Rösti
Packet Capture only lists interfaces that also appear on the Interface page. We chose not to show additional interfaces (such as the SSL VPN virtual interface) there, since users might otherwise think it's a bug rather than expected behavior.
Zyxel Melen0 -
But Melen you make it sound like the user is expecting a simple device when the USG is anything but that?
I take it thats why option like “override-direct-route” is not shown like it is in ZLD for advanced? Even if disabled by default?
0 -
Really strange to hear something like that.
Maybe I'm exceeding my own expectations (I run simple SME site), but if I'm down the rabbit hole with the Packet capturing, I'm already knowing what I'm doing and why shall I be confused then?
There are in fact much more advanced functionalities available on FLEX H platform in GUI, while tcpdump is a basic feature in networking area. IMHO, of course.
0 -
Hi @PeterUK
No, this question is not due to simple configuration GUI. I will say the device design will reference user's feedback. And this is like some user see anything seems wrong, they think this is a bug.
There are in fact much more advanced functionalities available on FLEX H platform in GUI, while tcpdump is a basic feature in networking area. IMHO, of course.
This is because some of our user use it wrongly in ZLD firewall. Therefore, we dicided this is an advanced configuration and can only use CLI to configure.
Zyxel Melen0 -
Hi @Rösti
Thanks for the detailed input — really useful context on how you're using FLEX H and user background. I've passed it along to our product team for consideration.
Zyxel Melen0 -
Yes Melen its a fine line between simple configuration GUI and advanced that the user use it wrongly in like ZLD firewall and seen it happen.
But I do think some options like override-direct-route should be added in the new uOS GUI
like the USG60 has the normal GUI and the simple GUI maybe for the new uOS have the the option for the normal GUI (like it is now) and advanced GUI?
0
Categories
- All Categories
- 442 Beta Program
- 3K Nebula
- 232 Nebula Ideas
- 132 Nebula Status and Incidents
- 6.7K Security
- 691 USG FLEX H Series
- 365 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 312 Service & License
- 505 News and Release
- 97 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.1K FAQ
- 34 Documents
- 89 About Community
- 112 Security Highlight
Zyxel Employee
Guru Member