<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet Captures issues in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/456206#M101687</link>
    <description>&lt;P&gt;That’s a great point Sutare. Let me verify it as it was not set by me.&lt;/P&gt;</description>
    <pubDate>Fri, 31 Dec 2021 04:54:19 GMT</pubDate>
    <dc:creator>d.spider</dc:creator>
    <dc:date>2021-12-31T04:54:19Z</dc:date>
    <item>
      <title>Packet Captures issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/455981#M101657</link>
      <description>&lt;P&gt;Hello Friends&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to take packet captures on my firewall. But in captures I do not see all the packets. What may be the issue? Am I missing anything?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 07:22:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/455981#M101657</guid>
      <dc:creator>d.spider</dc:creator>
      <dc:date>2021-12-30T07:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Captures issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/455985#M101658</link>
      <description>&lt;P&gt;Thank you for post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195649"&gt;@d.spider&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the first thing I would suspect is session offloading:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldYCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldYCAS&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 08:00:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/455985#M101658</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-12-30T08:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Captures issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/456006#M101662</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;Is that applicable to all firewall models? I see specific platforms in the article and mine is not listed there (PA 800 series).&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 11:20:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/456006#M101662</guid>
      <dc:creator>d.spider</dc:creator>
      <dc:date>2021-12-30T11:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Captures issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/456019#M101663</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195649"&gt;@d.spider&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;As you said you are not seeing all the packets in the capture, can you confirm what type of filter you have kept for the capture?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 12:54:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/456019#M101663</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-12-30T12:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Captures issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/456206#M101687</link>
      <description>&lt;P&gt;That’s a great point Sutare. Let me verify it as it was not set by me.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 04:54:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/456206#M101687</guid>
      <dc:creator>d.spider</dc:creator>
      <dc:date>2021-12-31T04:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Captures issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/456323#M101700</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195649"&gt;@d.spider&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I went through all documentation and it always states that session offloading is supported from PA-30XX/32XX series and higher, however I was looking into one of my PA-850 and I can see: "ctd decoder bypass" for some sessions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1641089799769.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38486i4FE0CD43708F62CE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1641089799769.png" alt="PavelK_0-1641089799769.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Even though it is not mentioned in documentation session offloading for PA-800 series seems supported.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you determined that session offloading is not an issue in your scenario, then as&amp;nbsp;&lt;SPAN&gt;Sutare mentioned maybe an issue is related to filters.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another thing that comes to my mind is, only new sessions will be recorded after packet capture is enabled, so you will not be able to capture traffic for sessions that are already established. Also, make sure to configure all stages to be sure you do not miss anything:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jan 2022 02:30:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/456323#M101700</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-01-02T02:30:27Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Captures issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/456359#M101708</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the explanation. The issue is resolved now. It was due to wrong filter. When I put filter from S2D and D2S, I can see all the packets captured in the pcap file. My mistake! I didn’t checked filter settings earlier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;for pointing out it.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jan 2022 07:09:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/456359#M101708</guid>
      <dc:creator>d.spider</dc:creator>
      <dc:date>2022-01-03T07:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Captures issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/456900#M101768</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/195649"&gt;@d.spider&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;You don't actually need to put filter for return traffic in order to capture it. I am guessing that &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp; was right and you don't capture on all stages. I would suggest you to take more detailed look on link that &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp; share.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Filters in packet capture are not working, the same way you imagine. Filter is not filtering packets, it is actually used to "tag" sessions. Based on the source and destination, firewall will search its connection table and tag any session that match the filter. Packets that belongs to tagged session will be captured. Or as the previous link explain it - "filters are session aware".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if you don't see return traffic when you use only source-to-destination filter, you definately not capturing on all stages - if I may guess not capturing transmit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By the way, this is also very good link that, could explain why there is too much noise in your captures (even if your filter is very strict) - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClgDCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClgDCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 07:59:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/456900#M101768</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-01-05T07:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Captures issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/457140#M101795</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The filter had all the required stages. Nothing was missing there. The filter had incorrect values. When filter point was highlighted, I referred below article while correcting the filter to make sure I am not missing anything. Here, it talks about the backup filters so I kept it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 01:07:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-captures-issues/m-p/457140#M101795</guid>
      <dc:creator>d.spider</dc:creator>
      <dc:date>2022-01-06T01:07:13Z</dc:date>
    </item>
  </channel>
</rss>

