Capturing Packets in MikroTik -TZSP Configuration. Contoso Ltd. /ip firewall mangle add action=sniff-tzsp chain=prerouting sniff-target=ip.of.wireshark.box sniff-target-port=port.of.wireshark.box By default TZSP is run on UDP/37008, so you can listen on UDP/37008 with your sniffing tools like wireshark