<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Interpret Traffic Monitor Output in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-interpret-traffic-monitor-output/m-p/50923#M37478</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please verify on the tunnel you have created you have proxy id setup for the subnet traffic that needs to go through the tunnel. However if you have both sides as palo alto then you do not need to set proxy id.&lt;/P&gt;&lt;P&gt;Here is a doc which explains why proxy ids are needed.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-3073"&gt;https://live.paloaltonetworks.com/docs/DOC-3073&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also if you still see the issue after verifying this you can use the following steps to troubleshoot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;1. Need to setup the filters for the traffic we are interested in. To do this, execute the following steps:&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Navigate to Monitor--Packet Capture&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Click 'Manage Filters'&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Set Filter ID 1 to be the source IP and destination IP of traffic you feel is affected ( leave all other fields blank )&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Set Filter ID 2 to be the exact inverse of what you did in step 3 (destination IP in source field, Source IP in destination field)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;2. Setup up the captures&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Create and name the file stage for a packet capture on all the stages (receive, transmit, firewall and drop)&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;3. Enable filters and captures &lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;debug dataplane packet-diag set filter on&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;debug dataplane packet-diag set capture on&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;4. open 2 CLI windows&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;on 1 run the following command to look at the counter ( make sure it run this command once before running the traffic)&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;show counter global filter packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;on the 2nd window run the following command to look at he sessions&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;show session all filter source &amp;lt;ip address&amp;gt; destination &amp;lt;ip address&amp;gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;After your test has been done stop all the captures and filters and see if global counter show you anything why it is dropping the traffic or if you have getting pcap with drop stage.&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;This will help you narrow down the issue.&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Let us know if this helps you resolve the issue.&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Thanks&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Numan&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/31070/edit" style="font-style: inherit; font-family: inherit; color: #316989;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Aug 2013 20:12:49 GMT</pubDate>
    <dc:creator>mbutt</dc:creator>
    <dc:date>2013-08-14T20:12:49Z</dc:date>
    <item>
      <title>How to Interpret Traffic Monitor Output</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-interpret-traffic-monitor-output/m-p/50921#M37476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have traffic going over a VPN tunnel. There is a rule alllowing the traffic and routing isn't a problem.&lt;/P&gt;&lt;P&gt;A source host isn't connecting to a host across the tunnel. In monitor I'm seeing entries that say the packet is allowed but in the application column the entry says "insufficient data". What does that mean?&amp;nbsp; Where can I find a list of expected entries for that column and what they mean?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 16:14:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-interpret-traffic-monitor-output/m-p/50921#M37476</guid>
      <dc:creator>Weese</dc:creator>
      <dc:date>2013-08-14T16:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to Interpret Traffic Monitor Output</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-interpret-traffic-monitor-output/m-p/50922#M37477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Wesse,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;STRONG style="font-style: inherit; font-family: inherit;"&gt;Insufficient data in the application field&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Insufficient data means that there was not enough data to identify the application. So for example, if the 3-way TCP handshake completed and there was one data packet after the handshake but that one data packet was not enough to match any of our signatures, you would see insufficient data in the application field of the traffic log.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1549"&gt;https://live.paloaltonetworks.com/docs/DOC-1549&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 16:18:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-interpret-traffic-monitor-output/m-p/50922#M37477</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-08-14T16:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to Interpret Traffic Monitor Output</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-interpret-traffic-monitor-output/m-p/50923#M37478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please verify on the tunnel you have created you have proxy id setup for the subnet traffic that needs to go through the tunnel. However if you have both sides as palo alto then you do not need to set proxy id.&lt;/P&gt;&lt;P&gt;Here is a doc which explains why proxy ids are needed.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-3073"&gt;https://live.paloaltonetworks.com/docs/DOC-3073&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also if you still see the issue after verifying this you can use the following steps to troubleshoot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;1. Need to setup the filters for the traffic we are interested in. To do this, execute the following steps:&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Navigate to Monitor--Packet Capture&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Click 'Manage Filters'&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Set Filter ID 1 to be the source IP and destination IP of traffic you feel is affected ( leave all other fields blank )&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Set Filter ID 2 to be the exact inverse of what you did in step 3 (destination IP in source field, Source IP in destination field)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;2. Setup up the captures&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Create and name the file stage for a packet capture on all the stages (receive, transmit, firewall and drop)&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;3. Enable filters and captures &lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;debug dataplane packet-diag set filter on&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;debug dataplane packet-diag set capture on&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;4. open 2 CLI windows&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;on 1 run the following command to look at the counter ( make sure it run this command once before running the traffic)&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;show counter global filter packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;on the 2nd window run the following command to look at he sessions&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;show session all filter source &amp;lt;ip address&amp;gt; destination &amp;lt;ip address&amp;gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;After your test has been done stop all the captures and filters and see if global counter show you anything why it is dropping the traffic or if you have getting pcap with drop stage.&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;This will help you narrow down the issue.&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Let us know if this helps you resolve the issue.&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Thanks&lt;/P&gt;&lt;P style="font-style: inherit; font-size: 11pt; font-family: Calibri;"&gt;Numan&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/31070/edit" style="font-style: inherit; font-family: inherit; color: #316989;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 20:12:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-interpret-traffic-monitor-output/m-p/50923#M37478</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-14T20:12:49Z</dc:date>
    </item>
  </channel>
</rss>

