<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic unknown traffic pcaps just stopped happening one day around 2 weeks ago in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unknown-traffic-pcaps-just-stopped-happening-one-day-around-2/m-p/517972#M486</link>
    <description>&lt;P&gt;I have a PA-460 that stopped doing pcaps for unknown traffic about two weeks ago.&amp;nbsp; I played around with the application dump setting and I think I may have broken something:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Application setting:&lt;BR /&gt;Application cache : yes&lt;BR /&gt;Supernode : yes&lt;BR /&gt;Heuristics : yes&lt;BR /&gt;Cache Threshold : 16&lt;BR /&gt;Bypass when exceeds queue limit: no&lt;BR /&gt;Traceroute appid : yes&lt;BR /&gt;Traceroute TTL threshold : 30&lt;BR /&gt;Use cache for appid : no&lt;BR /&gt;Use simple appsigs for ident : yes&lt;BR /&gt;Use AppID cache on SSL/SNI : no&lt;BR /&gt;Unknown capture : on&lt;BR /&gt;Max. unknown sessions : 5000&lt;BR /&gt;Current unknown sessions : 0&lt;BR /&gt;Application capture : off&lt;/P&gt;
&lt;P&gt;Current APPID Signature &lt;BR /&gt;Memory Usage : 4736 KB (Actual 4398 KB)&lt;BR /&gt;TCP 1 C2S : lscan db size 944448&lt;BR /&gt;TCP 1 S2C : lscan db size 727736&lt;BR /&gt;UDP 1 C2S : lscan db size 1086504&lt;BR /&gt;UDP 1 S2C : lscan db size 332968&lt;/P&gt;
&lt;P&gt;Alternate APPID Signature &lt;BR /&gt;Memory Usage : 4736 KB (Actual 4396 KB)&lt;BR /&gt;TCP 1 C2S : lscan db size 944128&lt;BR /&gt;TCP 1 S2C : lscan db size 727736&lt;BR /&gt;UDP 1 C2S : lscan db size 1086056&lt;BR /&gt;UDP 1 S2C : lscan db size 332968&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, if I do view-pcap application-pcap, the last date for an unknown application is around 2 weeks ago.&amp;nbsp; I may have set an application dump rule at that time; I can't remember for sure.&amp;nbsp; To verify, I started a netcat session in order to generate an unknown-tcp session, and checked the "current unknown sessions" counter.&amp;nbsp; It was still 0 while the netcat session was up, even though the unknown-tcp session was visible in the session browser.&amp;nbsp; I do realize that the firewall only samples unknowns and doesn't capture every session, but it doesn't seem to be capturing any.&amp;nbsp; Is there something I can do to get unknown-tcp pcaps working again?&lt;/P&gt;</description>
    <pubDate>Fri, 14 Oct 2022 16:05:50 GMT</pubDate>
    <dc:creator>DanielWaites</dc:creator>
    <dc:date>2022-10-14T16:05:50Z</dc:date>
    <item>
      <title>unknown traffic pcaps just stopped happening one day around 2 weeks ago</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unknown-traffic-pcaps-just-stopped-happening-one-day-around-2/m-p/517972#M486</link>
      <description>&lt;P&gt;I have a PA-460 that stopped doing pcaps for unknown traffic about two weeks ago.&amp;nbsp; I played around with the application dump setting and I think I may have broken something:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Application setting:&lt;BR /&gt;Application cache : yes&lt;BR /&gt;Supernode : yes&lt;BR /&gt;Heuristics : yes&lt;BR /&gt;Cache Threshold : 16&lt;BR /&gt;Bypass when exceeds queue limit: no&lt;BR /&gt;Traceroute appid : yes&lt;BR /&gt;Traceroute TTL threshold : 30&lt;BR /&gt;Use cache for appid : no&lt;BR /&gt;Use simple appsigs for ident : yes&lt;BR /&gt;Use AppID cache on SSL/SNI : no&lt;BR /&gt;Unknown capture : on&lt;BR /&gt;Max. unknown sessions : 5000&lt;BR /&gt;Current unknown sessions : 0&lt;BR /&gt;Application capture : off&lt;/P&gt;
&lt;P&gt;Current APPID Signature &lt;BR /&gt;Memory Usage : 4736 KB (Actual 4398 KB)&lt;BR /&gt;TCP 1 C2S : lscan db size 944448&lt;BR /&gt;TCP 1 S2C : lscan db size 727736&lt;BR /&gt;UDP 1 C2S : lscan db size 1086504&lt;BR /&gt;UDP 1 S2C : lscan db size 332968&lt;/P&gt;
&lt;P&gt;Alternate APPID Signature &lt;BR /&gt;Memory Usage : 4736 KB (Actual 4396 KB)&lt;BR /&gt;TCP 1 C2S : lscan db size 944128&lt;BR /&gt;TCP 1 S2C : lscan db size 727736&lt;BR /&gt;UDP 1 C2S : lscan db size 1086056&lt;BR /&gt;UDP 1 S2C : lscan db size 332968&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, if I do view-pcap application-pcap, the last date for an unknown application is around 2 weeks ago.&amp;nbsp; I may have set an application dump rule at that time; I can't remember for sure.&amp;nbsp; To verify, I started a netcat session in order to generate an unknown-tcp session, and checked the "current unknown sessions" counter.&amp;nbsp; It was still 0 while the netcat session was up, even though the unknown-tcp session was visible in the session browser.&amp;nbsp; I do realize that the firewall only samples unknowns and doesn't capture every session, but it doesn't seem to be capturing any.&amp;nbsp; Is there something I can do to get unknown-tcp pcaps working again?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 16:05:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/unknown-traffic-pcaps-just-stopped-happening-one-day-around-2/m-p/517972#M486</guid>
      <dc:creator>DanielWaites</dc:creator>
      <dc:date>2022-10-14T16:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: unknown traffic pcaps just stopped happening one day around 2 weeks ago</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unknown-traffic-pcaps-just-stopped-happening-one-day-around-2/m-p/517973#M487</link>
      <description>&lt;P&gt;For reference, this is 10.1.6-h6 on PA-460&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 16:07:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/unknown-traffic-pcaps-just-stopped-happening-one-day-around-2/m-p/517973#M487</guid>
      <dc:creator>DanielWaites</dc:creator>
      <dc:date>2022-10-14T16:07:01Z</dc:date>
    </item>
  </channel>
</rss>

