<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No transmit/drop in capture in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/no-transmit-drop-in-capture/m-p/492855#M104992</link>
    <description>&lt;P&gt;Hi Raji,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you explain what was the cause of this issue, we are experiencing the same&lt;/P&gt;</description>
    <pubDate>Thu, 26 May 2022 20:11:11 GMT</pubDate>
    <dc:creator>lealr1</dc:creator>
    <dc:date>2022-05-26T20:11:11Z</dc:date>
    <item>
      <title>No transmit/drop in capture</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-transmit-drop-in-capture/m-p/422829#M94098</link>
      <description>&lt;P&gt;What are the reasons we don't see transmit or drop in capture and traffic log shows traffic is allowed to/from correct zones, and tcp as age-out in logs.&amp;nbsp;Packets only show in receive/firewall stage. Alos checking flow basic, I do not see the packet at forwarding stage, although another firewall with same routes/policies and just different IP's works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;== 2021-07-28 15:31:42.692 -0700 ==&lt;BR /&gt;Packet received at ingress stage, tag 0, type ORDERED&lt;BR /&gt;Packet info: len 62 port 16 interface 16 vsys 1&lt;BR /&gt;wqe index 22530 packet 0x0xc00f5bb440, HA: 0, IC: 0&lt;BR /&gt;Packet decoded dump:&lt;BR /&gt;L2: c0:d6:82:94:8a:81-&amp;gt;00:0d:3a:e9:20:40, type 0x0800&lt;BR /&gt;IP: 172.23.5.4-&amp;gt;172.23.4.6, protocol 6&lt;BR /&gt;version 4, ihl 5, tos 0x00, len 48,&lt;BR /&gt;id 7359, frag_off 0x4000, ttl 128, checksum 53372(0x7cd0)&lt;BR /&gt;TCP: sport 29701, dport 91, seq 2582910416, ack 0,&lt;BR /&gt;reserved 0, offset 7, window 8192, checksum 56811,&lt;BR /&gt;flags 0x02 ( SYN), urgent data 0, l4 data len 0&lt;BR /&gt;TCP option:&lt;BR /&gt;00000000: 02 04 05 8a 01 01 04 02 ........&lt;BR /&gt;Flow lookup, key word0 0x60001005b7405 word1 0 word2 0x40517acffff0000 word3 0x0 word4 0x60417acffff0000&lt;BR /&gt;* Dos Profile NULL (NO) Index (0/0) *&lt;BR /&gt;Session setup: vsys 1&lt;BR /&gt;No active flow found, enqueue to create session&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;== 2021-07-28 15:31:42.692 -0700 ==&lt;BR /&gt;Packet received at slowpath stage, tag 1409011658, type ATOMIC&lt;BR /&gt;Packet info: len 62 port 16 interface 16 vsys 1&lt;BR /&gt;wqe index 22530 packet 0x0xc00f5bb440, HA: 0, IC: 0&lt;BR /&gt;Packet decoded dump:&lt;BR /&gt;L2: c0:d6:82:94:8a:81-&amp;gt;00:0d:3a:e9:20:40, type 0x0800&lt;BR /&gt;IP: 172.23.5.4-&amp;gt;172.23.4.6, protocol 6&lt;BR /&gt;version 4, ihl 5, tos 0x00, len 48,&lt;BR /&gt;id 7359, frag_off 0x4000, ttl 128, checksum 53372(0x7cd0)&lt;BR /&gt;TCP: sport 29701, dport 91, seq 2582910416, ack 0,&lt;BR /&gt;reserved 0, offset 7, window 8192, checksum 56811,&lt;BR /&gt;flags 0x02 ( SYN), urgent data 0, l4 data len 0&lt;BR /&gt;TCP option:&lt;BR /&gt;00000000: 02 04 05 8a 01 01 04 02 ........&lt;BR /&gt;Session setup: vsys 1&lt;BR /&gt;Session setup: ingress interface ethernet1/1 egress interface ethernet1/1 (zone 1)&lt;BR /&gt;NAT policy lookup, matched rule index 4&lt;BR /&gt;Destination NAT, translated IP 172.22.20.5&lt;BR /&gt;PBF lookup (vsys 1) with application none&lt;BR /&gt;Session setup: egress zone 2 for natted IP&lt;BR /&gt;Translated IP in zone 2, egress id 17&lt;BR /&gt;Policy lookup, matched rule index 3,&lt;BR /&gt;TCI_INSPECT: Do TCI lookup policy - appid 0&lt;BR /&gt;Allocated new session 8181.&lt;BR /&gt;set exclude_video in session 8181 0xe1438d3f80 0 from work 0xe056915800 0&lt;BR /&gt;Rule: index=4 name=APPGTW-TEST-SITES-443, cfg_pool_idx=3 cfg_fallback_pool_idx=0&lt;BR /&gt;NAT Rule: name=APPGTW-TEST-SITES-443, cfg_pool_idx=3; Session: index=8181, nat_pool_idx=3&lt;BR /&gt;Packet matched vsys 1 NAT rule 'APPGTW-TEST-SITES-443' (index 5),&lt;BR /&gt;source translation 172.23.5.4/29701 =&amp;gt; 172.23.68.6/59704&lt;BR /&gt;destination translation 172.23.4.6/91 =&amp;gt; 172.22.20.5/443&lt;BR /&gt;Created session, enqueue to install. work 0xe056915800 exclude_video 0,session 8181 0xe1438d3f80 exclude_video 0&lt;/P&gt;&lt;P&gt;* Dos Profile NULL (NO) Index (0/0) *&lt;/P&gt;&lt;P&gt;== 2021-07-28 15:31:42.693 -0700 ==&lt;BR /&gt;Packet received at fastpath stage, tag 8181, type ATOMIC&lt;BR /&gt;Packet info: len 62 port 16 interface 16 vsys 1&lt;BR /&gt;wqe index 22530 packet 0x0xc00f5bb440, HA: 0, IC: 0&lt;BR /&gt;Packet decoded dump:&lt;BR /&gt;L2: c0:d6:82:94:8a:81-&amp;gt;00:0d:3a:e9:20:40, type 0x0800&lt;BR /&gt;IP: 172.23.5.4-&amp;gt;172.23.4.6, protocol 6&lt;BR /&gt;version 4, ihl 5, tos 0x00, len 48,&lt;BR /&gt;id 7359, frag_off 0x4000, ttl 128, checksum 53372(0x7cd0)&lt;BR /&gt;TCP: sport 29701, dport 91, seq 2582910416, ack 0,&lt;BR /&gt;reserved 0, offset 7, window 8192, checksum 56811,&lt;BR /&gt;flags 0x02 ( SYN), urgent data 0, l4 data len 0&lt;BR /&gt;TCP option:&lt;BR /&gt;00000000: 02 04 05 8a 01 01 04 02 ........&lt;BR /&gt;Flow fastpath, session 8181 c2s (set work 0xe056915800 exclude_video 0 from sp 0xe1438d3f80 exclude_video 0)&lt;BR /&gt;IP checksum valid&lt;BR /&gt;* Dos Profile NULL (NO) Index (0/0) *&lt;BR /&gt;* Dos Profile NULL (NO) Index (0/0) *&lt;BR /&gt;2021-07-28 15:31:42.693 -0700 pan_flow_process_fastpath(src/pan_flow_proc.c:4022): SESSION-DSCP: set session DSCP: 0x00&lt;BR /&gt;NAT session, run address/port translation&lt;BR /&gt;Syn Cookie: pan_reass(Init statete): c2s:0 c2s:nxtseq 2582910417 c2s:startseq 2582910417 c2s:win 0 c2s:st 3 c2s:newsyn 0 :: s2c:nxtseq 0 s2c:startseq 0 s2c:win 8192 s2c:st 0 s2c:newsyn 0 ack &amp;#8; 0 nosyn 0 plen 0&lt;BR /&gt;CP-DENY TCP non data packet getting through&lt;BR /&gt;Forwarding lookup, ingress interface 16&lt;BR /&gt;L3 mode, virtual-router 2&lt;BR /&gt;Route lookup in virtual-router 2, IP 172.22.20.5&lt;BR /&gt;Route found, interface ethernet1/2, zone 2, nexthop 172.23.68.1&lt;BR /&gt;Resolve ARP for IP 172.23.68.1 on interface ethernet1/2&lt;BR /&gt;ARP entry found on interface 17&lt;BR /&gt;Transmit packet size 48 on port 17&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jul 2021 22:41:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-transmit-drop-in-capture/m-p/422829#M94098</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-07-28T22:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: No transmit/drop in capture</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-transmit-drop-in-capture/m-p/423000#M94127</link>
      <description>&lt;P&gt;it's sending packets out:&amp;nbsp;&lt;SPAN&gt;Transmit packet size 48 on port 17&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try adjusting your filter like this:&lt;/P&gt;&lt;P&gt;1. ip1 to ip2&lt;/P&gt;&lt;P&gt;2. ip3 to ip4&lt;/P&gt;&lt;P&gt;3. ip4 to ip3&lt;/P&gt;&lt;P&gt;4. ip2 to ip1&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 10:50:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-transmit-drop-in-capture/m-p/423000#M94127</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-07-29T10:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: No transmit/drop in capture</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-transmit-drop-in-capture/m-p/423340#M94152</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;I found the issue with custom routes in Azure, traffic was sent by internal interface of PA1 but received by PA2. After the fix I was able to see normal traffic. Would this be the reason of not seeing the forwarding stage. Its bit hard to troubleshoot such issues in cloud.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 06:59:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-transmit-drop-in-capture/m-p/423340#M94152</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2021-07-30T06:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: No transmit/drop in capture</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-transmit-drop-in-capture/m-p/492855#M104992</link>
      <description>&lt;P&gt;Hi Raji,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you explain what was the cause of this issue, we are experiencing the same&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 20:11:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-transmit-drop-in-capture/m-p/492855#M104992</guid>
      <dc:creator>lealr1</dc:creator>
      <dc:date>2022-05-26T20:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: No transmit/drop in capture</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/no-transmit-drop-in-capture/m-p/502858#M105373</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/72102"&gt;@lealr1&lt;/a&gt;&amp;nbsp;For us it was the issue with id-manager and had to reset it&lt;/P&gt;&lt;PRE&gt;debug device-server reset id-manager type all&lt;/PRE&gt;</description>
      <pubDate>Fri, 10 Jun 2022 21:09:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/no-transmit-drop-in-capture/m-p/502858#M105373</guid>
      <dc:creator>raji_toor</dc:creator>
      <dc:date>2022-06-10T21:09:16Z</dc:date>
    </item>
  </channel>
</rss>

