<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Detailed troubleshooting of drop counters in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24617#M17927</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please look on:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3938"&gt;https://live.paloaltonetworks.com/docs/DOC-3938&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does it make sense for your archie ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Oct 2013 11:23:39 GMT</pubDate>
    <dc:creator>VinceM</dc:creator>
    <dc:date>2013-10-28T11:23:39Z</dc:date>
    <item>
      <title>Detailed troubleshooting of drop counters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24616#M17926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having some issues with odd packet drops, and "show counter global filter severity drop" shows a lot of packets being dropped due to "Packets dropped: 802.1q tag not configured/Packets dropped: invalid interface" (same amount of packets dropped on both, so I assume these are related).&lt;/P&gt;&lt;P&gt;Are there any way of getting a log of what has been happening for flow_rcv_dot1q_tag_err and flow_no_interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just knowing that the firewall is dropping packets doesn't help a lot when I'm unable to get any further information about the traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 09:01:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24616#M17926</guid>
      <dc:creator>arvesynd</dc:creator>
      <dc:date>2013-10-28T09:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: Detailed troubleshooting of drop counters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24617#M17927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please look on:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3938"&gt;https://live.paloaltonetworks.com/docs/DOC-3938&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does it make sense for your archie ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 11:23:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24617#M17927</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-10-28T11:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Detailed troubleshooting of drop counters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24618#M17928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vince,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, it does make sense, as all the Cisco devices in our network are running pvst, but the few of our remaining Dell PowerConnect switches seems to be unable to handle pvst.&lt;/P&gt;&lt;P&gt;We are troubleshooting some major issues with the network, and I would like to see the traffic that the firewall is dropping to see if this is related.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the firewall is logging that the traffic is being dropped, it should also log the actual traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 13:45:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24618#M17928</guid>
      <dc:creator>arvesynd</dc:creator>
      <dc:date>2013-10-28T13:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: Detailed troubleshooting of drop counters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24619#M17929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi you can do the captures on the firewall to see what traffic is being dropped. However this should be used only for the troubleshooting purposes in short burst. If you leave it running the pcap exceeds certain limit a new pcap file will be generated. But again this is CPU intensive and should be used only for troubleshooting.&lt;/P&gt;&lt;P&gt;In captures there are 4 different stages recieve, transmit, Drop and firewall. The drop pcap should show you what is being dropped by the firewall. Here are some additional tips as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;1. Need to setup the filters for the traffic we are interested in. To do this, execute the following steps:&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Navigate to Monitor--Packet Capture&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Click 'Manage Filters'&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Set Filter ID 1 to be the source IP and destination IP of traffic you feel is affected ( leave all other fields blank )&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Set Filter ID 2 to be the exact inverse of what you did in step 3 (destination IP in source field, Source IP in destination field)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;2. Setup up the captures&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Create and name the file stage for a packet capture on all the stages (receive, transmit, firewall and drop)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;3. Enable filters and captures &lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;debug dataplane packet-diag set filter on&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;debug dataplane packet-diag set capture on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;4. open 2 CLI windows&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;on 1 run the following command to look at the counter ( make sure it run this command once before running the traffic)&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;show counter global filter packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;on the 2nd window run the following command to look at he sessions&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;show session all filter source &amp;lt;ip address&amp;gt; destination &amp;lt;ip address&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;After your test has been done stop all the captures and filters and see if global counter show you anything why it is dropping the traffic or if you have getting pcap with drop stage.&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;This will help you narrow down the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Let us know if this helps you resolve the issue.&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Thanks&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 15:33:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24619#M17929</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-10-28T15:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: Detailed troubleshooting of drop counters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24620#M17930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi mbutt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. I am aware of the packet capture feature, and I have used it to some extent, but I still can't help but feel that this is a huge detour for a problem that the firewall has detected, and done something about.&lt;/P&gt;&lt;P&gt;When troubleshooting PANOS compared to other manufacturers, I feel like the PAN firewall is hiding a lot of what it's actually doing from me, and instead focusing on presenting the traffic that runs smoothly with nice graphs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 06:58:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24620#M17930</guid>
      <dc:creator>arvesynd</dc:creator>
      <dc:date>2013-10-29T06:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Detailed troubleshooting of drop counters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24621#M17931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I completely agree with you. We were troubleshooting issues&lt;BR /&gt;with packets being dropped and found it very hard to impossible to actually&lt;BR /&gt;find out why a packet is dropped. If the firewall drops a packet I should be&lt;BR /&gt;able to see a report or enter a CLI command to find out why and how many. I’m&lt;BR /&gt;actually filing a feature request for this. It just seems so basic, I can’t believe&lt;BR /&gt;it is so difficult. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Nov 2013 23:53:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24621#M17931</guid>
      <dc:creator>ldavie</dc:creator>
      <dc:date>2013-11-13T23:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: Detailed troubleshooting of drop counters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24622#M17932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can follow this document and get a details information about any drop counter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3199"&gt;How to Enable Logging for Global Counters?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;To enable logging for global counters, run the following command via CLI:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-family: 'courier new', courier;"&gt;&lt;SPAN class="GINGER_SOFATWARE_correct"&gt;debug&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFATWARE_correct"&gt;dataplane&lt;/SPAN&gt; packet-&lt;SPAN class="GINGER_SOFATWARE_correct"&gt;diag&lt;/SPAN&gt; set log counter &amp;lt;counter name Example:"&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;STRONG&gt;&lt;EM&gt;flow_rcv_dot1q_tag_err and flow_no_interface&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;"&amp;gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt; &lt;IMG __jive_id="9763" alt="global-counter.JPG.jpg" class="jive-image" height="99" src="https://live.paloaltonetworks.com/legacyfs/online/9763_global-counter.JPG.jpg" style="width: 916.1194029850747px; height: 99px;" width="916" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;You will be able to see the same logs under Monitor&amp;gt;&amp;gt; System logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;To disable logging, run:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-style: inherit; font-family: 'courier new', courier;"&gt;&lt;SPAN class="GINGER_SOFATWARE_correct"&gt;debug&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFATWARE_correct"&gt;dataplane&lt;/SPAN&gt; packet-&lt;SPAN class="GINGER_SOFATWARE_correct"&gt;diag&lt;/SPAN&gt; clear log counter &amp;lt;counter_name&amp;gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2013 01:53:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/detailed-troubleshooting-of-drop-counters/m-p/24622#M17932</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-11-14T01:53:15Z</dc:date>
    </item>
  </channel>
</rss>

