<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic packet capture for unknown-tcp in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-for-unknown-tcp/m-p/2016#M1477</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm getting a lot of unknown-tcp on the internal network and would like to capture some packets to get an idea what this is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried:&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set capture trigger application from unknown-tcp to unknown-tcp&lt;/P&gt;&lt;P&gt;but I don't get any packets so far.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried from none to unknown-tcp, same result, nothing captured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea what I'm doing wrong or a better idea how to capture that unknown traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt; Andreas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Aug 2012 17:02:20 GMT</pubDate>
    <dc:creator>idelconsulting</dc:creator>
    <dc:date>2012-08-30T17:02:20Z</dc:date>
    <item>
      <title>packet capture for unknown-tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-for-unknown-tcp/m-p/2016#M1477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm getting a lot of unknown-tcp on the internal network and would like to capture some packets to get an idea what this is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried:&lt;/P&gt;&lt;P&gt;debug dataplane packet-diag set capture trigger application from unknown-tcp to unknown-tcp&lt;/P&gt;&lt;P&gt;but I don't get any packets so far.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried from none to unknown-tcp, same result, nothing captured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea what I'm doing wrong or a better idea how to capture that unknown traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt; Andreas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2012 17:02:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-for-unknown-tcp/m-p/2016#M1477</guid>
      <dc:creator>idelconsulting</dc:creator>
      <dc:date>2012-08-30T17:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: packet capture for unknown-tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-for-unknown-tcp/m-p/2017#M1478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Andreas&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest updating and the Application database to the latest version.&lt;/P&gt;&lt;P&gt;Also try&amp;nbsp; trigger condition from application "unknown " to "unknown-tcp".&lt;/P&gt;&lt;P&gt;These document might be helpful:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-2007"&gt;https://live.paloaltonetworks.com/docs/DOC-2007&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-2542"&gt;https://live.paloaltonetworks.com/docs/DOC-2542&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2012 18:46:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-for-unknown-tcp/m-p/2017#M1478</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-08-30T18:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: packet capture for unknown-tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-for-unknown-tcp/m-p/2018#M1479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ameya,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the links. I knew most of it but not all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Application DB is the latest version.&lt;/P&gt;&lt;P&gt;In this case I'm observing mainframe traffic, there are not many mainframe apps in the application DB.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; Andreas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2012 20:09:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-for-unknown-tcp/m-p/2018#M1479</guid>
      <dc:creator>idelconsulting</dc:creator>
      <dc:date>2012-08-30T20:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: packet capture for unknown-tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-for-unknown-tcp/m-p/2019#M1480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Did you get a chance to change the&amp;nbsp; trigger condition from application "unknown " to "unknown-tcp".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&amp;gt;debug dataplane packet-diag set capture trigger application from &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;unknown&lt;/SPAN&gt; to unknown-tcp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If this doesn't work you could try configuring packet filters based on destination-port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is a multi-dataplane platform eg 5k there are few other settings needed to capture exact packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Aug 2012 00:48:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-for-unknown-tcp/m-p/2019#M1480</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-08-31T00:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: packet capture for unknown-tcp</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-for-unknown-tcp/m-p/2020#M1481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andreas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can enable this command to packetcapture unknown application packets:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; set application dump-unknown yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the pcaps will appear in the traffic log as a little green arrow or from the CLI in "view-pcap application-pcap &amp;lt;date&amp;gt;/"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2012 10:07:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-for-unknown-tcp/m-p/2020#M1481</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2012-09-07T10:07:09Z</dc:date>
    </item>
  </channel>
</rss>

