<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic iMac updates and traffic monitoring in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/imac-updates-and-traffic-monitoring/m-p/31679#M23170</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have permitted apple-updates and users have confirmed that they are able to perform their updates. However, a user in is unable to perform updates as it appears that he is being blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All our firewall and filtering is carried out by PAN and I am usually view traffic from a user's PC computer and figure out what is being blocked by the one of the Palo Altos.&amp;nbsp; However, in this case I am unable to see traffic sourced or destined from his iMac. Yes he is connected to our network (connected concurrently to our wireless and wired networks) and to no other. When I go into Panorama and look at the traffic logs I do not see any traffic at all to or from his iMac. Yes, he is able to browse but I am not able to see his traffic. I am only filtering for his IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas as to how or why the I am unable to see his traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Aug 2013 17:28:46 GMT</pubDate>
    <dc:creator>PeterG</dc:creator>
    <dc:date>2013-08-19T17:28:46Z</dc:date>
    <item>
      <title>iMac updates and traffic monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/imac-updates-and-traffic-monitoring/m-p/31679#M23170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have permitted apple-updates and users have confirmed that they are able to perform their updates. However, a user in is unable to perform updates as it appears that he is being blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All our firewall and filtering is carried out by PAN and I am usually view traffic from a user's PC computer and figure out what is being blocked by the one of the Palo Altos.&amp;nbsp; However, in this case I am unable to see traffic sourced or destined from his iMac. Yes he is connected to our network (connected concurrently to our wireless and wired networks) and to no other. When I go into Panorama and look at the traffic logs I do not see any traffic at all to or from his iMac. Yes, he is able to browse but I am not able to see his traffic. I am only filtering for his IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas as to how or why the I am unable to see his traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 17:28:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/imac-updates-and-traffic-monitoring/m-p/31679#M23170</guid>
      <dc:creator>PeterG</dc:creator>
      <dc:date>2013-08-19T17:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: iMac updates and traffic monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/imac-updates-and-traffic-monitoring/m-p/31680#M23171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To be sure check for policies if logging is enabled for related rule(s) or not&lt;/P&gt;&lt;P&gt;also for deep investigation you may take packet capture to see if that ip traffic comes to firewall or not.&lt;/P&gt;&lt;P&gt;also look directly to device(or context) not panorama.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 17:45:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/imac-updates-and-traffic-monitoring/m-p/31680#M23171</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-19T17:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: iMac updates and traffic monitoring</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/imac-updates-and-traffic-monitoring/m-p/31681#M23172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can do the following inorder to verify if the traffic is coming to the firewall and is getting blocked&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;1. Need to setup the filters for the traffic you are interested in. To do this, execute the following steps:&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Navigate to Monitor--Packet Capture&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Click 'Manage Filters'&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Set Filter ID 1 to be the source IP and destination IP of traffic you feel is affected ( leave all other fields blank )&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Set Filter ID 2 to be the exact inverse of what you did in step 3 (destination IP in source field, Source IP in destination field)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;2. Setup up the captures&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Create and name the file stage for a packet capture on all the stages (receive, transmit, firewall and drop)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;3. Enable filters and captures &lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;debug dataplane packet-diag set filter on&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;debug dataplane packet-diag set capture on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;4. open 2 CLI windows&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;on 1 run the following command to look at the counter ( make sure to run this command once before running the traffic)&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;show counter global filter packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;on the 2nd window run the following command to look at he sessions&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;show session all filter source &amp;lt;ip address&amp;gt; destination &amp;lt;ip address&amp;gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;if you dont have the destination that is fine just leave the above command till source&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;After your test has been done stop all the captures and filters and see if global counter show you anything why it is dropping the traffic or if you have getting pcap with drop stage.&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;This will help you narrow down the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Let us know if this helps you resolve the issue.&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Thanks&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11pt;"&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 18:01:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/imac-updates-and-traffic-monitoring/m-p/31681#M23172</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-19T18:01:07Z</dc:date>
    </item>
  </channel>
</rss>

