<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using packet capture to view DHCP discover , offer , request and ACK packet in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-packet-capture-to-view-dhcp-discover-offer-request-and-ack/m-p/67700#M39649</link>
    <description>&lt;P&gt;You can setup a specific security rule to just look for the DHCP application. This way the traffic will display in the Traffic logs. Also if I remember my DHCP correctly, the client send the request to the DHCP server over port 67 but then the server replies over port 68.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 05 Nov 2015 15:50:44 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2015-11-05T15:50:44Z</dc:date>
    <item>
      <title>Using packet capture to view DHCP discover , offer , request and ACK packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-packet-capture-to-view-dhcp-discover-offer-request-and-ack/m-p/67686#M39639</link>
      <description>&lt;P&gt;how can we view DHCP discover , offer , request and ACK packet&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 08:11:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-packet-capture-to-view-dhcp-discover-offer-request-and-ack/m-p/67686#M39639</guid>
      <dc:creator>fatboy1607</dc:creator>
      <dc:date>2015-11-05T08:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: Using packet capture to view DHCP discover , offer , request and ACK packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-packet-capture-to-view-dhcp-discover-offer-request-and-ack/m-p/67688#M39641</link>
      <description>&lt;P&gt;You can see all if dhcp server and client are in diferent subnets so those packets pass Palo or if Palo itself is dhcp server.&lt;/P&gt;
&lt;P&gt;If server and client are in same subnet then discover is broadcast but from then on server sends response directly to client and devices standing by don't see this (unless you use mirror port is switch).&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 10:42:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-packet-capture-to-view-dhcp-discover-offer-request-and-ack/m-p/67688#M39641</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-11-05T10:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: Using packet capture to view DHCP discover , offer , request and ACK packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-packet-capture-to-view-dhcp-discover-offer-request-and-ack/m-p/67693#M39643</link>
      <description>&lt;P&gt;thanks but I am looking for specific command we can run on palo alto to view DORA exchange.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for example using tcpdump -i &amp;lt;interface&amp;gt; port 67 we get that information.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 13:17:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-packet-capture-to-view-dhcp-discover-offer-request-and-ack/m-p/67693#M39643</guid>
      <dc:creator>fatboy1607</dc:creator>
      <dc:date>2015-11-05T13:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Using packet capture to view DHCP discover , offer , request and ACK packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-packet-capture-to-view-dhcp-discover-offer-request-and-ack/m-p/67700#M39649</link>
      <description>&lt;P&gt;You can setup a specific security rule to just look for the DHCP application. This way the traffic will display in the Traffic logs. Also if I remember my DHCP correctly, the client send the request to the DHCP server over port 67 but then the server replies over port 68.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 15:50:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-packet-capture-to-view-dhcp-discover-offer-request-and-ack/m-p/67700#M39649</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-11-05T15:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: Using packet capture to view DHCP discover , offer , request and ACK packet</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-packet-capture-to-view-dhcp-discover-offer-request-and-ack/m-p/67776#M39669</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You won't see the specific packets in the traffic logs, but if it's for diagnostic purpose, you can start a capture from the GUI and specify the DHCP ports as the filter. You will be able to download the resulting capture and analyze it in Wireshark.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Sat, 07 Nov 2015 04:37:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-packet-capture-to-view-dhcp-discover-offer-request-and-ack/m-p/67776#M39669</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2015-11-07T04:37:49Z</dc:date>
    </item>
  </channel>
</rss>

