<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Management Interface traffic logs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/management-interface-traffic-logs/m-p/157881#M51723</link>
    <description>&lt;P&gt;One big advantage of Palo is seperate dataplane (network ports, HA2, HA3) and control plane (mgmt port, HA1).&lt;/P&gt;&lt;P&gt;Even smallest 2 core firewall has one cpu core dedicated for checking passthrough traffic and other for management.&lt;/P&gt;&lt;P&gt;As a result you can manage the box even if you are under attack or your dataplane is fully utilized.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For that reason you can't use regular packet capture but have to use tcpdump that&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;&amp;nbsp;pointed out.&lt;/P&gt;</description>
    <pubDate>Tue, 23 May 2017 13:54:14 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2017-05-23T13:54:14Z</dc:date>
    <item>
      <title>Management Interface traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-interface-traffic-logs/m-p/157870#M51721</link>
      <description>Hi guys,&lt;BR /&gt;&lt;BR /&gt;Is there a way to see traffic logs of management traffic? I'm trying to troubleshoot user-id redistribution source from the management interface.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;NetWorkZeus</description>
      <pubDate>Tue, 23 May 2017 13:17:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-interface-traffic-logs/m-p/157870#M51721</guid>
      <dc:creator>networkzeus</dc:creator>
      <dc:date>2017-05-23T13:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Management Interface traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-interface-traffic-logs/m-p/157878#M51722</link>
      <description>&lt;P&gt;MGMT (out of band interface) cannot be a part of the&amp;nbsp;zone, so no traffic logs can be generated. but you still can do a PCAP if that is helps;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-To-Packet-Capture-tcpdump-On-Management-Interface/ta-p/55415" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-To-Packet-Capture-tcpdump-On-Management-Interface/ta-p/55415&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 13:26:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-interface-traffic-logs/m-p/157878#M51722</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-05-23T13:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Management Interface traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-interface-traffic-logs/m-p/157881#M51723</link>
      <description>&lt;P&gt;One big advantage of Palo is seperate dataplane (network ports, HA2, HA3) and control plane (mgmt port, HA1).&lt;/P&gt;&lt;P&gt;Even smallest 2 core firewall has one cpu core dedicated for checking passthrough traffic and other for management.&lt;/P&gt;&lt;P&gt;As a result you can manage the box even if you are under attack or your dataplane is fully utilized.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For that reason you can't use regular packet capture but have to use tcpdump that&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;&amp;nbsp;pointed out.&lt;/P&gt;</description>
      <pubDate>Tue, 23 May 2017 13:54:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-interface-traffic-logs/m-p/157881#M51723</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-05-23T13:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: Management Interface traffic logs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/management-interface-traffic-logs/m-p/158461#M51842</link>
      <description>&lt;P&gt;Awesome thats what I was after!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2017 12:21:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/management-interface-traffic-logs/m-p/158461#M51842</guid>
      <dc:creator>networkzeus</dc:creator>
      <dc:date>2017-05-26T12:21:28Z</dc:date>
    </item>
  </channel>
</rss>

