<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: show counter interface management multicast packets dropped in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/233861#M67036</link>
    <description>&lt;P&gt;there are no packets listed where i can see multicast. but your filter will only capture packets where 192.168.1.10 is involved (i guess its your local management ip of your pa-220). so if there is multicast which is dropped (not&amp;nbsp;answered by your pa) you would never see it with your packet filter (host 192.168.1.10).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the traffic i can see for now is only arp with your gateway (192.168.1.20) i guess and dns traffic with the name server. thats ok.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Oct 2018 10:46:43 GMT</pubDate>
    <dc:creator>markus_w</dc:creator>
    <dc:date>2018-10-04T10:46:43Z</dc:date>
    <item>
      <title>show counter interface management multicast packets dropped</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/233109#M66863</link>
      <description>&lt;P&gt;show counter interface management&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Interface: Management Interface&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Logical interface counters:&lt;BR /&gt;-------------------------------------------------------------------------------&lt;BR /&gt;bytes received 50983020707&lt;BR /&gt;bytes transmitted 1703516003&lt;BR /&gt;packets received 38137194&lt;BR /&gt;packets transmitted 18673283&lt;BR /&gt;receive errors 0&lt;BR /&gt;transmit errors 0&lt;BR /&gt;&lt;STRONG&gt;receive packets dropped 1971053&lt;/STRONG&gt;&lt;BR /&gt;transmit packets dropped 0&lt;BR /&gt;&lt;STRONG&gt;multicast packets received 1971053&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;need to know why PA is dropping these packets?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;from where they are coming?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Mike&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Sep 2018 16:25:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/233109#M66863</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-09-30T16:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: show counter interface management multicast packets dropped</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/233174#M66884</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;you can do a packet capture on the mangement interface and find it out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Didn't know it exactly which type of packets this counter hits, but maybe your management interface have a list of permitted ip addresses in the config and these packets came from devices not on the list?!?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2018 11:34:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/233174#M66884</guid>
      <dc:creator>markus_w</dc:creator>
      <dc:date>2018-10-01T11:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: show counter interface management multicast packets dropped</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/233275#M66904</link>
      <description>&lt;P&gt;Management interface is configured for any IP addresses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;tcpdump filter "host 192.168.1.10 and port not 22 and not 443"&lt;BR /&gt;Press Ctrl-C to stop capturing&lt;/P&gt;&lt;P&gt;tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 68 bytes&lt;BR /&gt;^C4 packets captured&lt;BR /&gt;8 packets received by filter&lt;BR /&gt;0 packets dropped by kernel&lt;BR /&gt;mparmar2@PA-220&amp;gt; view-pcap mgmt-pcap mgmt.pcap&lt;BR /&gt;19:40:13.782669 IP 192.168.1.10.58468 &amp;gt; nsc1.so.cg.shawcable.net.domain:&amp;nbsp; 39907+[|domain]&lt;BR /&gt;19:40:13.782697 IP 192.168.1.10.58468 &amp;gt; nsc1.so.cg.shawcable.net.domain:&amp;nbsp; 10687+[|domain]&lt;BR /&gt;19:40:13.797919 IP nsc1.so.cg.shawcable.net.domain &amp;gt; 192.168.1.10.58468:&amp;nbsp; 39907[|domain]&lt;BR /&gt;19:40:13.798329 IP nsc1.so.cg.shawcable.net.domain &amp;gt; 192.168.1.10.58468:&amp;nbsp; 10687[|domain]&lt;BR /&gt;mparmar2@PA-220&amp;gt; tcpdump filter "host 192.168.1.10 and port not 22 and not 443"&lt;BR /&gt;Press Ctrl-C to stop capturing&lt;/P&gt;&lt;P&gt;tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 68 bytes&lt;BR /&gt;^C6 packets captured&lt;BR /&gt;12 packets received by filter&lt;BR /&gt;0 packets dropped by kernel&lt;BR /&gt;mparmar2@PA-220&amp;gt; view-pcap mgmt-pcap mgmt.pcap&lt;BR /&gt;19:41:18.770752 arp who-has 192.168.1.20 tell 192.168.1.10&lt;BR /&gt;19:41:18.770930 arp reply 192.168.1.20 is-at b0:fa:eb:a2:cb:cb (oui Unknown)&lt;BR /&gt;19:41:29.512025 IP 192.168.1.10.59224 &amp;gt; nsc1.so.cg.shawcable.net.domain:&amp;nbsp; 5217+[|domain]&lt;BR /&gt;19:41:29.512051 IP 192.168.1.10.59224 &amp;gt; nsc1.so.cg.shawcable.net.domain:&amp;nbsp; 6919+[|domain]&lt;BR /&gt;19:41:29.527328 IP nsc1.so.cg.shawcable.net.domain &amp;gt; 192.168.1.10.59224:&amp;nbsp; 5217[|domain]&lt;BR /&gt;19:41:29.527642 IP nsc1.so.cg.shawcable.net.domain &amp;gt; 192.168.1.10.59224:&amp;nbsp; 6919[|domain]&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 01:42:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/233275#M66904</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-02T01:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: show counter interface management multicast packets dropped</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/233276#M66905</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/8014"&gt;@PA&lt;/a&gt;-220&amp;gt; view-pcap mgmt-pcap mgmt.pcap&lt;BR /&gt;19:42:47.902330 IP 192.168.1.10.60433 &amp;gt; nsc1.so.cg.shawcable.net.domain:&amp;nbsp; 57606+[|domain]&lt;BR /&gt;19:42:47.902355 IP 192.168.1.10.60433 &amp;gt; nsc1.so.cg.shawcable.net.domain:&amp;nbsp; 46160+[|domain]&lt;BR /&gt;19:42:47.917557 IP nsc1.so.cg.shawcable.net.domain &amp;gt; 192.168.1.10.60433:&amp;nbsp; 57606[|domain]&lt;BR /&gt;19:42:47.917901 IP nsc1.so.cg.shawcable.net.domain &amp;gt; 192.168.1.10.60433:&amp;nbsp; 46160[|domain]&lt;BR /&gt;19:43:52.770748 arp who-has 192.168.1.20 tell 192.168.1.10&lt;BR /&gt;19:43:52.770921 arp reply 192.168.1.20 is-at b0:fa:eb:a2:cb:cb (oui Unknown)&lt;BR /&gt;19:44:13.492580 IP 192.168.1.10.54095 &amp;gt; nsc1.so.cg.shawcable.net.domain:&amp;nbsp; 64697+[|domain]&lt;BR /&gt;19:44:13.492610 IP 192.168.1.10.54095 &amp;gt; nsc1.so.cg.shawcable.net.domain:&amp;nbsp; 60268+[|domain]&lt;BR /&gt;19:44:13.520459 IP nsc1.so.cg.shawcable.net.domain &amp;gt; 192.168.1.10.54095:&amp;nbsp; 64697[|domain]&lt;BR /&gt;19:44:13.521289 IP nsc1.so.cg.shawcable.net.domain &amp;gt; 192.168.1.10.54095:&amp;nbsp; 60268[|domain]&lt;BR /&gt;19:45:18.550772 arp who-has 192.168.1.20 tell 192.168.1.10&lt;BR /&gt;19:45:18.550911 arp reply 192.168.1.20 is-at b0:fa:eb:a2:cb:cb (oui Unknown)&lt;BR /&gt;19:45:52.940757 arp who-has 192.168.1.20 tell 192.168.1.10&lt;BR /&gt;19:45:52.940905 arp reply 192.168.1.20 is-at b0:fa:eb:a2:cb:cb (oui Unknown)&lt;BR /&gt;19:45:54.122667 IP 192.168.1.10.35815 &amp;gt; nsc1.so.cg.shawcable.net.domain:&amp;nbsp; 6767+[|domain]&lt;BR /&gt;19:45:54.122698 IP 192.168.1.10.35815 &amp;gt; nsc1.so.cg.shawcable.net.domain:&amp;nbsp; 10019+[|domain]&lt;BR /&gt;19:45:54.163938 IP nsc1.so.cg.shawcable.net.domain &amp;gt; 192.168.1.10.35815:&amp;nbsp; 6767[|domain]&lt;BR /&gt;19:45:54.164306 IP nsc1.so.cg.shawcable.net.domain &amp;gt; 192.168.1.10.35815:&amp;nbsp; 10019[|domain]&lt;BR /&gt;19:46:13.472925 IP 192.168.1.10.35585 &amp;gt; nsc1.so.cg.shawcable.net.domain:&amp;nbsp; 57846+[|domain]&lt;BR /&gt;19:46:13.472954 IP 192.168.1.10.35585 &amp;gt; nsc1.so.cg.shawcable.net.domain:&amp;nbsp; 46565+[|domain]&lt;BR /&gt;19:46:13.487259 IP nsc1.so.cg.shawcable.net.domain &amp;gt; 192.168.1.10.35585:&amp;nbsp; 57846[|domain]&lt;BR /&gt;19:46:13.487626 IP nsc1.so.cg.shawcable.net.domain &amp;gt; 192.168.1.10.35585:&amp;nbsp; 46565[|domain]&lt;BR /&gt;19:47:18.760755 arp who-has 192.168.1.20 tell 192.168.1.10&lt;BR /&gt;19:47:18.760912 arp reply 192.168.1.20 is-at b0:fa:eb:a2:cb:cb (oui Unknown)&lt;/P&gt;</description>
      <pubDate>Tue, 02 Oct 2018 01:49:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/233276#M66905</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-02T01:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: show counter interface management multicast packets dropped</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/233861#M67036</link>
      <description>&lt;P&gt;there are no packets listed where i can see multicast. but your filter will only capture packets where 192.168.1.10 is involved (i guess its your local management ip of your pa-220). so if there is multicast which is dropped (not&amp;nbsp;answered by your pa) you would never see it with your packet filter (host 192.168.1.10).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the traffic i can see for now is only arp with your gateway (192.168.1.20) i guess and dns traffic with the name server. thats ok.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 10:46:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/233861#M67036</guid>
      <dc:creator>markus_w</dc:creator>
      <dc:date>2018-10-04T10:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: show counter interface management multicast packets dropped</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/233889#M67042</link>
      <description>&lt;P&gt;or maybe there are devices in the network with ipv6 enabled. ipv6 uses multicast (no broadcasts). if the mangement interface had no ipv6 configuration enabled it will probably drop those ipv6 multicasts.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 11:35:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/233889#M67042</guid>
      <dc:creator>markus_w</dc:creator>
      <dc:date>2018-10-04T11:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: show counter interface management multicast packets dropped</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/234233#M67151</link>
      <description>&lt;P&gt;seems on management interface ipv6 is not configured.&lt;/P&gt;&lt;P&gt;is there any way on PA we can find source of ipv6 traffic?&lt;/P&gt;</description>
      <pubDate>Sat, 06 Oct 2018 01:52:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/234233#M67151</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-06T01:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: show counter interface management multicast packets dropped</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/234234#M67152</link>
      <description>&lt;P&gt;yes 192.168.1.10 is management ip of pa&lt;/P&gt;</description>
      <pubDate>Sat, 06 Oct 2018 01:55:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/show-counter-interface-management-multicast-packets-dropped/m-p/234234#M67152</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2018-10-06T01:55:11Z</dc:date>
    </item>
  </channel>
</rss>

