<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto firewall does not display traffic log in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222501#M63987</link>
    <description>&lt;P&gt;You have only MGMT interface configured and pinging that?&amp;nbsp;PA has out of band MGMT interface which is seperated from the FW functions.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jul 2018 08:40:43 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2018-07-17T08:40:43Z</dc:date>
    <item>
      <title>Palo Alto firewall does not display traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222462#M63981</link>
      <description>&lt;DIV class="postcell post-layout--right"&gt;&lt;DIV class="post-text"&gt;&lt;P&gt;I've just installed Palo Alto firewall VM version in virtual box.&lt;/P&gt;&lt;P&gt;I was able to access it via WEB (https) and SSH.&lt;/P&gt;&lt;P&gt;However, when I check traffic log it was empty.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA traffic log.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15936iC6F017DE158E51B6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA traffic log.jpg" alt="PA traffic log.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I generated a few traffic such as ping and nmap scan against firewall IP, but still no traffic log appear in it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;log-receiver statistics shows 0 traffic logs written meaning no traffic at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've also restarted `log-receiver` as advised in &lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Traffic-Log-is-Not-Generated-and-Not-Displayed-on-the-WebGUI/ta-p/62177" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Traffic-Log-is-Not-Generated-and-Not-Displayed-on-the-WebGUI/ta-p/62177&lt;/A&gt; but didn't help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;admin@PA-VM&amp;gt; debug software restart log-receiver

Process 'logrcvr' executing RESTART

admin@PA-VM&amp;gt; &lt;/PRE&gt;&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What went wrong with this firewall and how to fix it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;admin@PA-VM&amp;gt; debug log-receiver statistics

Logging statistics
------------------------------ -----------
Log incoming rate:             0/sec
Log written rate:              0/sec
Corrupted packets:             0
Corrupted URL packets:         0
Corrupted HTTP HDR packets:    0
Logs discarded (queue full):   0
Traffic logs written:          0
URL logs written:              0
Wildfire logs written:         0
Anti-virus logs written:       0
Widfire Anti-virus logs written: 0
Spyware logs written:          0
Attack logs written:           0
Vulnerability logs written:    0
Fileext logs written:          0
URL cache age out count:       0
URL cache full count:          0
URL cache key exist count:     0
URL cache wrt incomplete http hdrs count: 0
URL cache rcv http hdr before url count: 0
URL cache full drop count(url log not received): 0
URL cache age out drop count(url log not received): 0
Traffic alarms dropped due to sysd write failures: 0
Traffic alarms dropped due to global rate limiting: 0
Traffic alarms dropped due to each source rate limiting: 0
Traffic alarms generated count:  0
Log Forward count:             0
Log Forward discarded (queue full) count: 0
Log Forward discarded (send error) count: 0

Summary Statistics:
Num current drop entries in trsum:0
Num cumulative drop entries in trsum:0
Num current drop entries in thsum:0
Num cumulative drop entries in thsum:0

External Forwarding stats:
      Type  Enqueue Count     Send Count     Drop Count    Queue Depth     Send Rate(last 1min)
    syslog              0              0              0              0                        0
      snmp              0              0              0              0                        0
     email              0              0              0              0                        0
       raw              0              0              0              0                        0

admin@PA-VM&amp;gt; &lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 17 Jul 2018 02:20:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222462#M63981</guid>
      <dc:creator>prenatip</dc:creator>
      <dc:date>2018-07-17T02:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall does not display traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222498#M63986</link>
      <description>&lt;P&gt;Are your default rules actualy set to log??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 08:03:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222498#M63986</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-07-17T08:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall does not display traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222501#M63987</link>
      <description>&lt;P&gt;You have only MGMT interface configured and pinging that?&amp;nbsp;PA has out of band MGMT interface which is seperated from the FW functions.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 08:40:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222501#M63987</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-07-17T08:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall does not display traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222669#M64033</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71756"&gt;@RobinClayton&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Are your default rules actualy set to log??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, here is the screenshot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Security Policy Rule.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15955iCB7371CD962717A1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Security Policy Rule.jpg" alt="Security Policy Rule.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 05:34:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222669#M64033</guid>
      <dc:creator>prenatip</dc:creator>
      <dc:date>2018-07-18T05:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall does not display traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222671#M64034</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;You have only MGMT interface configured and pinging that?&amp;nbsp;PA has out of band MGMT interface which is seperated from the FW functions.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks ... I do configure another interface, but still don't see any changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This time, I can't even ping internal ip of Palo Alto firewall from another Client.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Here is my topology. Has anyone successfully setup a lab of PA in VirtualBox before?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Client (10.1.1.110) --&amp;gt; PA (10.1.1.254)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;VirtualBox Adapter setting&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;VirtualBox Adapter 1: Host-only (out of band MGMT interface)&lt;/P&gt;&lt;P&gt;VirtualBox Adapter 2: Internal Network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Palo Alto interface setting&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ethernet Interface.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15956iD46C7607A93C46E8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Ethernet Interface.jpg" alt="Ethernet Interface.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;admin@PA-VM&amp;gt; show interface all

total configured hardware interfaces: 1

name                    id    speed/duplex/state        mac address       
--------------------------------------------------------------------------------
ethernet1/1             16    1000/full/up              bb:bb:bb:bb:bb:bb 

aggregation groups: 0


total configured logical interfaces: 1

name                id    vsys zone             forwarding               tag    address                          
               
------------------- ----- ---- ---------------- ------------------------ ------ ------------------
ethernet1/1         16    1                     N/A                      0      10.1.1.254/32     

admin@PA-VM&amp;gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Client Config&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;user@linux:~$ ifconfig | grep ad | grep -v 127
eth0      Link encap:Ethernet  HWaddr 00:00:00:AA:AA:A1  
          inet addr:192.168.56.110  Bcast:192.168.56.255  Mask:255.255.255.0
eth1      Link encap:Ethernet  HWaddr 00:00:00:AA:AA:A2  
          inet addr:10.1.1.110  Bcast:10.1.1.255  Mask:255.255.255.0
user@linux:~$ &lt;/PRE&gt;&lt;P&gt;&lt;STRONG&gt;Ping test from Client to Palo Alto internal interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;user@linux:~$ ping 10.1.1.254 -c 5
PING 10.1.1.254 (10.1.1.254): 56 data bytes

--- 10.1.1.254 ping statistics ---
5 packets transmitted, 0 packets received, 100% packet loss
user@linux:~$ &lt;/PRE&gt;&lt;P&gt;&lt;STRONG&gt;ARP Entry on client&lt;/STRONG&gt;&lt;/P&gt;&lt;PRE&gt;user@linux:~$ arp
? (192.168.56.1) at 00:00:00:00:00:11 [ether]  on eth0
? (192.168.56.254) at aa:aa:aa:aa:aa:a1 [ether]  on eth0
? (10.1.1.254) at &amp;lt;incomplete&amp;gt;  on eth1
user@linux:~$ &lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ARP Entry on PA fw&lt;/STRONG&gt;&lt;/P&gt;&lt;PRE&gt;admin@PA-VM&amp;gt; show arp all

maximum of entries supported :      500
default timeout:                    1800 seconds
total ARP entries in table :        0
total ARP entries shown :           0
status: s - static, c - complete, e - expiring, i - incomplete

interface         ip address      hw address        port              status   ttl  
--------------------------------------------------------------------------------

admin@PA-VM&amp;gt; &lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 06:05:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222671#M64034</guid>
      <dc:creator>prenatip</dc:creator>
      <dc:date>2018-07-18T06:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall does not display traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222673#M64035</link>
      <description>&lt;P&gt;You will never see any traffic to MGMT interface in traffic log as that interface is not a part of firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you don't get MAC address of PA non-mgmt IP then you have issues at layers below level 3. So untill you get&amp;nbsp;MAC address you won't be able to send any traffic to PA.&amp;nbsp;So logs will remain empty till then.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 06:19:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222673#M64035</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2018-07-18T06:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall does not display traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222697#M64040</link>
      <description>&lt;P&gt;have you set a managemetn profile on the lan interface?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 07:57:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222697#M64040</guid>
      <dc:creator>RobinClayton</dc:creator>
      <dc:date>2018-07-18T07:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto firewall does not display traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222709#M64043</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;You will never see any traffic to MGMT interface in traffic log as that interface is not a part of firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you don't get MAC address of PA non-mgmt IP then you have issues at layers below level 3. So untill you get&amp;nbsp;MAC address you won't be able to send any traffic to PA.&amp;nbsp;So logs will remain empty till then.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/10238"&gt;@santonic&lt;/a&gt;, based on ARP and tcpdump output, I suspect this is Layer 1 issue between VirtualBox and PA-VM&amp;nbsp;ethernet1/1 interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've open seperate topic for this ... let me know if you need more info.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/PA-VM-network-setting-in-VirtualBox/m-p/222701#M64042" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/PA-VM-network-setting-in-VirtualBox/m-p/222701#M64042&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 08:27:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-firewall-does-not-display-traffic-log/m-p/222709#M64043</guid>
      <dc:creator>prenatip</dc:creator>
      <dc:date>2018-07-18T08:27:11Z</dc:date>
    </item>
  </channel>
</rss>

