How does packet logging work?
The NetScreen-IDP is capable of logging raw packets when an attack is detected. The security administrator can define in the rulebase how many packets before and after the attack the system should log. When an attack is detected, the sensor logs the packets, as defined by the rule. The user can then access these packets from the logs using the management interface. By obtaining the raw packets, the security administrator can precisely see what the hacker was attempting to do on the network. These packets can also be exported to third party tools for replaying the attack.