<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What are these mysterious pcaps? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-are-these-mysterious-pcaps/m-p/14727#M10812</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/29784"&gt;rvandegrift&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where are you seeing these captures ? I think these might be getting captured due to one of the security profiles like for some of the threat pcap/extended pcap takes place.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Dec 2014 22:04:03 GMT</pubDate>
    <dc:creator>bat</dc:creator>
    <dc:date>2014-12-16T22:04:03Z</dc:date>
    <item>
      <title>What are these mysterious pcaps?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-are-these-mysterious-pcaps/m-p/14726#M10811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've noticed a boatload of application-pcaps - between 5-15k, on days where they are captured.&amp;nbsp; There are captures from most days, but not every day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I know, I don't have any traffic captures enabled.&amp;nbsp; All of the following show that captures are disabled:&lt;/P&gt;&lt;P&gt;1. debug dataplane packet-diag show setting (capture and logs disabled on all dataplanes)&lt;/P&gt;&lt;P&gt;2. show running application setting (unknown capture and application capture are disabled)&lt;/P&gt;&lt;P&gt;3. debug ike pcap show (no ipsec config anyhow)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What else could be triggering these captures?&amp;nbsp; Maybe they are used as a part of some firewall feature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is on PA-5060 running 6.0.5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ross&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Dec 2014 22:01:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-are-these-mysterious-pcaps/m-p/14726#M10811</guid>
      <dc:creator>rvandegrift</dc:creator>
      <dc:date>2014-12-16T22:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: What are these mysterious pcaps?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-are-these-mysterious-pcaps/m-p/14727#M10812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/29784"&gt;rvandegrift&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where are you seeing these captures ? I think these might be getting captured due to one of the security profiles like for some of the threat pcap/extended pcap takes place.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Dec 2014 22:04:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-are-these-mysterious-pcaps/m-p/14727#M10812</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-12-16T22:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: What are these mysterious pcaps?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-are-these-mysterious-pcaps/m-p/14728#M10813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's it - it looks like we have an AV profile that has a capture set for some hits.&amp;nbsp; Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ross&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Dec 2014 22:12:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-are-these-mysterious-pcaps/m-p/14728#M10813</guid>
      <dc:creator>rvandegrift</dc:creator>
      <dc:date>2014-12-16T22:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: What are these mysterious pcaps?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-are-these-mysterious-pcaps/m-p/14729#M10814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ross,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may check the configured AV profile, in casepcapenabled on it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt; &lt;IMG alt="AV-profile.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/17342_AV-profile.JPG" style="height: 420px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Dec 2014 06:18:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-are-these-mysterious-pcaps/m-p/14729#M10814</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-12-17T06:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: What are these mysterious pcaps?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-are-these-mysterious-pcaps/m-p/14730#M10815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I thought this was it, but nope - I disabled the AV profile packet capture yesterday, but there are thousands of new pcaps today:&lt;/P&gt;&lt;P&gt;admin@firewall(active-primary)&amp;gt; view-pcap application-pcap 20141217/&lt;/P&gt;&lt;P&gt;Display all 16625 possibilities? (y or n) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've exported the device config and the Panorama config to grep through.&amp;nbsp; All capture options are disabled in both places.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there conditions under which a device might capture packets anyhow?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ross&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Dec 2014 22:27:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-are-these-mysterious-pcaps/m-p/14730#M10815</guid>
      <dc:creator>rvandegrift</dc:creator>
      <dc:date>2014-12-17T22:27:28Z</dc:date>
    </item>
  </channel>
</rss>

