<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic monitor incomplete in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-monitor-incomplete/m-p/472022#M103170</link>
    <description>&lt;P&gt;My monitor is showing traffic from this IP.&amp;nbsp; It was from previous connections to the gateway.&amp;nbsp; It is a new portal/gateway.&amp;nbsp; Yes, it has a security policy, all settings are correct as far as I'm seeing.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Mar 2022 15:45:23 GMT</pubDate>
    <dc:creator>danoman2</dc:creator>
    <dc:date>2022-03-10T15:45:23Z</dc:date>
    <item>
      <title>Traffic monitor incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-monitor-incomplete/m-p/471721#M103131</link>
      <description>&lt;P&gt;I've got a new Global Protect portal/gateway.&amp;nbsp; When I get connected to the gateway, I can see the connection via the GP monitor.&amp;nbsp; Then if I go the to traffic monitor and search the source range 192.168.203.0/24 I only get traffic from previous testing that I've performed.&amp;nbsp; I'm not getting the currently connected device to show up for some reason.&amp;nbsp; It's connected as the remote user option in the network&amp;gt;gateway shows me connected and the ip of 192.168.203.2.&amp;nbsp; However its not in the monitor.&amp;nbsp; What do you all think?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 20:11:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-monitor-incomplete/m-p/471721#M103131</guid>
      <dc:creator>danoman2</dc:creator>
      <dc:date>2022-03-09T20:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic monitor incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-monitor-incomplete/m-p/471765#M103137</link>
      <description>&lt;P&gt;Do you have a "receive_time" or interface/source/zone filter in you log view? If this is a new gateway/portal, did you create a new Security Policy rule allowing the traffic from the new interface/zone/IPs but didn't check the log options in the policy action?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 22:47:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-monitor-incomplete/m-p/471765#M103137</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-03-09T22:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic monitor incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-monitor-incomplete/m-p/472022#M103170</link>
      <description>&lt;P&gt;My monitor is showing traffic from this IP.&amp;nbsp; It was from previous connections to the gateway.&amp;nbsp; It is a new portal/gateway.&amp;nbsp; Yes, it has a security policy, all settings are correct as far as I'm seeing.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 15:45:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-monitor-incomplete/m-p/472022#M103170</guid>
      <dc:creator>danoman2</dc:creator>
      <dc:date>2022-03-10T15:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic monitor incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-monitor-incomplete/m-p/472030#M103172</link>
      <description>&lt;P&gt;It's kind of hard to guess without details. I have seen a few errata in the release notes for various versions about edge cases where traffic wasn't being logged, but I don't recall anything specific about new gateways. Maybe open a support ticket with PA where you can share the details with them and they can see if it is something obvious.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 16:00:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-monitor-incomplete/m-p/472030#M103172</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2022-03-10T16:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic monitor incomplete</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/traffic-monitor-incomplete/m-p/472205#M103187</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/133096"&gt;@danoman2&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You probably have "log at session end" configured for your security policy rules.&amp;nbsp; This is recommended.&amp;nbsp; Monitor &amp;gt; Logs &amp;gt; Traffic will only show sessions that have &lt;EM&gt;ended&lt;/EM&gt;.&amp;nbsp; In order to see live sessions, go to Monitor &amp;gt; Session Browser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 01:39:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/traffic-monitor-incomplete/m-p/472205#M103187</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-03-11T01:39:59Z</dc:date>
    </item>
  </channel>
</rss>

