<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the reason for packet capture? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-reason-for-packet-capture/m-p/7658#M5656</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a setting somewhere if unknown traffic should be captured or not by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason is to have a sample to send for analysis if needed (or investage on your own) - for example in order to create a custom appid (either on your own or by support from PaloAlto).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The packetcapture can also be setup for various IPS and (I think) AV signatures - same here to have a sample in case false positive occurs or such.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Mar 2013 20:14:02 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-03-04T20:14:02Z</dc:date>
    <item>
      <title>What is the reason for packet capture?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-reason-for-packet-capture/m-p/7657#M5655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We recently flattened our lab firewall and configured it as a tap firewall. It currently has only one security policy which is an allow all policy. The firewall currently has one zone and the only other non-standard default config is a handful of custom applications and application overrides.&lt;/P&gt;&lt;P&gt;What I did was set a filter in the traffic logs of "flags has pcap" and surprisingly to me, there were actual packet captures. The traffic consisted of unknown-tcp and udp, incomplete data and a couple of traceroutes. However, it doesn't capture packets for all of any one of those categories, which begs the question:&lt;/P&gt;&lt;P&gt;Why is the firewall capturing data from seemingly random traffic from the categories of unknown-tcp, unknown-udp, incomplete data and traceroute?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2013 20:10:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-reason-for-packet-capture/m-p/7657#M5655</guid>
      <dc:creator>bgranholm</dc:creator>
      <dc:date>2013-03-04T20:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: What is the reason for packet capture?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-reason-for-packet-capture/m-p/7658#M5656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a setting somewhere if unknown traffic should be captured or not by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason is to have a sample to send for analysis if needed (or investage on your own) - for example in order to create a custom appid (either on your own or by support from PaloAlto).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The packetcapture can also be setup for various IPS and (I think) AV signatures - same here to have a sample in case false positive occurs or such.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2013 20:14:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-reason-for-packet-capture/m-p/7658#M5656</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-03-04T20:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: What is the reason for packet capture?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-reason-for-packet-capture/m-p/7659#M5657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have combed the firewall for that setting and I am not finding it. I have default settings for the security profiles and I don't have them applied anywhere. Anyone else want to take a shot?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2013 21:13:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-reason-for-packet-capture/m-p/7659#M5657</guid>
      <dc:creator>bgranholm</dc:creator>
      <dc:date>2013-03-04T21:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: What is the reason for packet capture?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-reason-for-packet-capture/m-p/7660#M5658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please refer the following docs:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="4734" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="2221" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2013 03:04:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-reason-for-packet-capture/m-p/7660#M5658</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-03-05T03:04:32Z</dc:date>
    </item>
  </channel>
</rss>

