<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Impact of run tcpdump on every interface. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/impact-of-run-tcpdump-on-every-interface/m-p/575963#M115626</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We need to execute tcpdump in PA-VM for a specific reason. We need to TCPdump data from firewalls for 15 minutes at various intervals; there is no specified source or destination. When we run tcpdump from every interface, we want to know if it has any effect? The current utilization&lt;/P&gt;
&lt;P&gt;Management CPU 15% &lt;BR /&gt;Data Plane CPU 65% &lt;BR /&gt;Session Count 2484 / 819200&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And details of Firewall is bellow:&lt;/P&gt;
&lt;P&gt;VM License VM-300&lt;BR /&gt;VM Capacity Tier 9.0 GB&lt;BR /&gt;VM Mode Microsoft Azure&lt;BR /&gt;Software Version 11.0.2&lt;BR /&gt;GlobalProtect Agent 6.1.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Nipon&lt;/P&gt;</description>
    <pubDate>Mon, 05 Feb 2024 05:34:55 GMT</pubDate>
    <dc:creator>Nipon-Deb-Sify</dc:creator>
    <dc:date>2024-02-05T05:34:55Z</dc:date>
    <item>
      <title>Impact of run tcpdump on every interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/impact-of-run-tcpdump-on-every-interface/m-p/575963#M115626</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We need to execute tcpdump in PA-VM for a specific reason. We need to TCPdump data from firewalls for 15 minutes at various intervals; there is no specified source or destination. When we run tcpdump from every interface, we want to know if it has any effect? The current utilization&lt;/P&gt;
&lt;P&gt;Management CPU 15% &lt;BR /&gt;Data Plane CPU 65% &lt;BR /&gt;Session Count 2484 / 819200&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And details of Firewall is bellow:&lt;/P&gt;
&lt;P&gt;VM License VM-300&lt;BR /&gt;VM Capacity Tier 9.0 GB&lt;BR /&gt;VM Mode Microsoft Azure&lt;BR /&gt;Software Version 11.0.2&lt;BR /&gt;GlobalProtect Agent 6.1.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Nipon&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 05:34:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/impact-of-run-tcpdump-on-every-interface/m-p/575963#M115626</guid>
      <dc:creator>Nipon-Deb-Sify</dc:creator>
      <dc:date>2024-02-05T05:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Impact of run tcpdump on every interface.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/impact-of-run-tcpdump-on-every-interface/m-p/576008#M115627</link>
      <description>&lt;P&gt;do you have an indication of your bandwidth usage?&lt;/P&gt;
&lt;P&gt;the built-in packetcapture will only allow you to capture up to 200mb, roll over to a new file and then another 200mb, but then the rollover is rolled over (i.e. you can have a maximum of 400mb captured per capture type rx/tx/fw/drp)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;unless you apply filters, 15 minutes does not seem feasible&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd worry less about CPU usage at this point&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 09:19:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/impact-of-run-tcpdump-on-every-interface/m-p/576008#M115627</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-02-05T09:19:42Z</dc:date>
    </item>
  </channel>
</rss>

