FortiGate_Transparent # dia sni pac any "host 192.168.1.222 and icmp" 4
interfaces=[any]
filters=[host 192.168.1.222 and icmp]
0.765120 VLAN111 in 192.168.1.111 -> 192.168.1.222: icmp: echo request
0.765133 VLAN222 out 192.168.1.111 -> 192.168.1.222: icmp: echo request
0.765136 port1 out 192.168.1.111 -> 192.168.1.222: icmp: echo request
0.769002 VLAN222 in 192.168.1.222 -> 192.168.1.111: icmp: echo reply
0.769012 VLAN111 out 192.168.1.222 -> 192.168.1.111: icmp: echo reply
0.769014 port1 out 192.168.1.222 -> 192.168.1.111: icmp: echo reply
1.779012 VLAN111 in 192.168.1.111 -> 192.168.1.222: icmp: echo request
1.779032 VLAN222 out 192.168.1.111 -> 192.168.1.222: icmp: echo request
1.779035 port1 out 192.168.1.111 -> 192.168.1.222: icmp: echo request
1.783557 VLAN222 in 192.168.1.222 -> 192.168.1.111: icmp: echo reply
1.783568 VLAN111 out 192.168.1.222 -> 192.168.1.111: icmp: echo reply
1.783570 port1 out 192.168.1.222 -> 192.168.1.111: icmp: echo reply
2.793025 VLAN111 in 192.168.1.111 -> 192.168.1.222: icmp: echo request
2.793039 VLAN222 out 192.168.1.111 -> 192.168.1.222: icmp: echo request
2.793042 port1 out 192.168.1.111 -> 192.168.1.222: icmp: echo request
2.796745 VLAN222 in 192.168.1.222 -> 192.168.1.111: icmp: echo reply
2.796754 VLAN111 out 192.168.1.222 -> 192.168.1.111: icmp: echo reply
2.796756 port1 out 192.168.1.222 -> 192.168.1.111: icmp: echo reply
在FGT的Port1上镜像抓包:
分析一个PC1 ping PC2的过程 VLAN TAG的变化,非常直接的可以看到请求报文的VLAN-TAG从111变成了222,回复报文的VLAN-TAG从222变成了111,实现了remapping VlanID的功能。