Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

How to allow non-root users to set full packet capture

From Tech-Wiki


ScreenOS procedure for allowing non-root administrators to run detailed packet captures.

!
Legacy / version-specific guidance
This is ScreenOS/NetScreen guidance, not current Junos OS guidance. Retain it only for legacy ScreenOS appliances.
ⓘ
Validation status
Reviewed during the Tech-Wiki Wave 3 migration on 27 September 2026. The historical procedure is retained for engineers supporting older estates, but is not presented as the default approach for a new deployment.
!
Privilege expansion and reboot
The historical setting broadens packet-capture privileges and requires a reboot. Do not apply it to an SRX/Junos device.

Historical procedure

In ScreenOS 5.4 or later, by default, only the root administrators can run 'snoop detail' which allows for a full size packet capture.

In order to allow the read/write administrators to run snoop detail, the environment variable can be set or unset by root administrator.

set envar allow_snoop_detail_by_all=yes

The firewall needs to then be is rebooted, at which point read/write administrators are permitted to use the ‘snoop detail'.

To remove this behaviour the following command needs to be set by the root administrator:

unset envar allow_snoop_detail_by_all

Once again the firewall needs to be rebooted to change the firewall back to the default behavior.