Inline enforcement and signature detection
Keep firewalls, IDS, and IPS in control. Investigate the decision.
Firewalls, IDS, and IPS enforce policy and raise detections in real time. PacketSafari works after the event, using an authorized PCAP to verify protocol behavior, timing, coverage, and the evidence behind an escalation.
Allow, deny, inspect, detect, and prevent traffic according to policy, signatures, threat intelligence, and session state.
Capture from a firewall export where supported, an adjacent TAP or packet broker, SPAN, cloud mirror, recorder, or endpoint.
Explain the selected conversation and validate the observed enforcement outcome without replacing the inline policy or prevention product.
Representative products
Different jobs. One clean handoff.
These are representative ecosystem products, not partner badges or certification claims. Capabilities and packet access vary by edition, license, deployment, and configuration.
NGFW and threat prevention
Session, threat, and policy logs; packet capture is workflow-specific.
ComplementaryExplain the packets associated with a rule, reset, threat, or application decision.
NGFW, IPS, application control, and SD-WAN
Logs and diagnostic capture options; retention is deployment-specific.
ComplementaryVerify traffic behavior around an enforcement or performance event.
Firewall and threat prevention
Policy and threat telemetry; obtain a bounded capture through the approved path.
ComplementaryAdd frame-level evidence to a gateway-led investigation.
Firewall, IPS, and application visibility
Event context and diagnostic packet capture depending on platform.
ComplementaryInvestigate the exact exchange associated with an alert or access failure.
NGFW and secure routing
Flow and security telemetry; packet acquisition is architecture-specific.
ComplementarySeparate network, peer, and application behavior with packet timing.
NGFW and synchronized security
Firewall logs and diagnostic captures.
ComplementaryTurn a selected capture into evidence for the security or service owner.
Network intrusion prevention
IPS events and traffic context; raw packet access depends on deployment.
ComplementaryVerify exploit-path or false-positive questions against the packet record.
IDS, IPS, and network security monitoring
Alerts, protocol logs, and optional PCAP ecosystem workflows.
ComplementaryInvestigate the capture beyond the signature hit and document the conclusion.
Signature-based IDS and IPS
Alert identifies the packet question; PCAP can be retained separately.
ComplementaryTest scope, sequence, and surrounding traffic beyond the matching packet.
Evidence to bring with the PCAP
Reconstruct the enforcement chain.
The PCAP shows observable wire behavior. These control records establish what the gateway recognized, decided, and attempted.
Policy and session records
Preserve the matched rule, application or signature classification, session lifecycle, and disposition.
Action telemetry
Correlate generated RST, drop, reject, intercept, proxy, or bypass actions with exact packet timing.
Gateway deployment context
Record the deployed software, detection content, policy package, and feature state.
Identity and address context
Use RADIUS, NAT, and CFLOW records to resolve the user, translated tuple, direction, and enforcement point.
Decision guide
Use each layer for the decision it owns.
Keep each layer in its strongest role: the platform detects or enforces, the visibility stack acquires traffic, and PacketSafari investigates the selected capture.
Do you need to enforce policy inline?
Use the firewall or IPS. PacketSafari does not sit inline or block traffic.
Do you need to validate an alert or explain a disputed enforcement outcome?
Acquire the incident window and use PacketSafari to test the exact exchange, supplied control context, wire action, and endpoint behavior.
Is traffic encrypted?
Use authorized decryption or an observation point where the required evidence is visible; otherwise report the visibility limit explicitly.

