Cisco Cisco Firepower Management Center 4000

Seite von 1844
 
18-28
FireSIGHT System User Guide
 
Chapter 18      Working with Intrusion Events 
  Using the Packet View
Protocols in frame
The protocols included in the frame.
Viewing Data Link Layer Information
License: 
Protection
On the packet view, click the arrow next to the data link layer protocol (for example, 
Ethernet II
) to view 
the data link layer information about the packet, which contains the 48-bit media access control (MAC) 
addresses for the source and destination hosts. It may also display other information about the packet, 
depending on the hardware protocol.
Note
Note that this example discusses Ethernet link layer information; other protocols may also appear.
The packet view reflects the protocol used at the data link layer. The following listing describes the 
information you might see for an Ethernet II or IEEE 802.3 Ethernet packet in the packet view. 
Destination
The MAC address for the destination host.
Note
Ethernet can also use multicast and broadcast addresses as the destination address.
Source
The MAC address for the source host.
Type
For Ethernet II packets, the type of packet that is encapsulated in the Ethernet frame; for example, 
IPv6 or ARP datagrams. Note that this item only appears for Ethernet II packets. 
Length
For IEEE 802.3 Ethernet packets, the total length of the packet, in bytes, not including the 
checksum. Note that this item only appears for IEEE 802.3 Ethernet packets.
Viewing Network Layer Information
License: 
Protection
On the packet view, click the arrow next to the network layer protocol (for example, 
Internet Protocol
) to 
view more detailed information about network layer information related to the packet.
Note
Note that this example discusses IP packets; other protocols may also appear.
See the following sections for more information:
  •
  •