<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Current session/connection information by subnet in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/current-session-connection-information-by-subnet/m-p/18788#M13689</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess you could also make a dedicated (temporary) firewall rule for the specific traffic you are interested in and then do a :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show session all filter rule xxx&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Sep 2011 09:19:53 GMT</pubDate>
    <dc:creator>Bart_Jocque</dc:creator>
    <dc:date>2011-09-27T09:19:53Z</dc:date>
    <item>
      <title>Current session/connection information by subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/current-session-connection-information-by-subnet/m-p/18785#M13686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;We're trying to isolate the source of some high session traffic in one of our regions. This is showing up in our exterior firewall connection count, and also on our PA device which is in line.&lt;/P&gt;&lt;P&gt;I can see the sessions by using the command line tools and filtering to see which interface/zones/application they're from, but I can find no way of narrowing down which networks the sessions are coming from.&lt;/P&gt;&lt;P&gt;The IP information is available in the session info, but for instance I can't seem to do a search based on IP masks .e.g. "show session all count yes filter source 192.168.100.0/24" would show me a total session count for anything originating in that network - I'm limited to individual addresses. The same appears true for the Session Browser in the GUI.&lt;/P&gt;&lt;P&gt;Is there a way of filtering by source network for current session info? Can I export a session browser view and analyse it elsewhere? Any other ideas?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;John Bousfield&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2011 14:08:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/current-session-connection-information-by-subnet/m-p/18785#M13686</guid>
      <dc:creator>aveva_palo</dc:creator>
      <dc:date>2011-09-26T14:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: Current session/connection information by subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/current-session-connection-information-by-subnet/m-p/18786#M13687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;﻿﻿if you are using plain /24 or /16 mask , you can use the match command :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g. :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show session all filter | match 192.168.1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Sep 2011 07:26:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/current-session-connection-information-by-subnet/m-p/18786#M13687</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2011-09-27T07:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: Current session/connection information by subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/current-session-connection-information-by-subnet/m-p/18787#M13688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;That's a useful command to know, but doesn't resolve my query unfortunately because I can't then do a count on that result. I just get a list of the matching entries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried outputting the result of "show session all filter from zone_name" to log, then counting the lines, but they do not match the "count yes" argument results by a factor for 10 - e.g. lines are ~2000, count is 20,000. I'm not sure I can trust the results in that case&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other alternatives?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Sep 2011 09:15:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/current-session-connection-information-by-subnet/m-p/18787#M13688</guid>
      <dc:creator>aveva_palo</dc:creator>
      <dc:date>2011-09-27T09:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: Current session/connection information by subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/current-session-connection-information-by-subnet/m-p/18788#M13689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess you could also make a dedicated (temporary) firewall rule for the specific traffic you are interested in and then do a :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show session all filter rule xxx&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Sep 2011 09:19:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/current-session-connection-information-by-subnet/m-p/18788#M13689</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2011-09-27T09:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: Current session/connection information by subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/current-session-connection-information-by-subnet/m-p/18789#M13690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the gui you can filter traffic using subnets. You can click on a sigle IP&amp;nbsp; in the traffic log that is showing the behavior you are investigating to add it to the filter. Then edit the IP from 10.10.10.10 to 10.10.0.0/16.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CLI does not support this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Sep 2011 18:31:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/current-session-connection-information-by-subnet/m-p/18789#M13690</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2011-09-30T18:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Current session/connection information by subnet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/current-session-connection-information-by-subnet/m-p/18790#M13691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In "show session all filter ... " command, there is also count option. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;admin@PAN&amp;gt; show session all filter count yes source 192.168.22.201&lt;BR /&gt;Number of sessions that match filter: 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you cannot do subnets with that and this only looks at sessions which are active at that time. Otherwise best option is to export your traffic logs as CSV and use MS Excel or similar to sort and count.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Oct 2011 03:40:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/current-session-connection-information-by-subnet/m-p/18790#M13691</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2011-10-01T03:40:08Z</dc:date>
    </item>
  </channel>
</rss>

