<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet capture filters in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9465#M6946</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Santonic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Try command "debug software restart vardata." let me know if that fix the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;You will have to reconfigure capture/filter after that.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Jul 2014 14:39:10 GMT</pubDate>
    <dc:creator>hshah</dc:creator>
    <dc:date>2014-07-25T14:39:10Z</dc:date>
    <item>
      <title>Packet capture filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9462#M6943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone else have problems with defining filters for packet capture in WebUI?&lt;/P&gt;&lt;P&gt;If I understand correctly (there is no info about this in official documentation) all values in the same filter are logically connected with 'AND' operator. And logical operation between different filters is 'OR'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if I want to monitor all traffic between 2 hosts i need something like this:&lt;/P&gt;&lt;P&gt;1st filter ID 1: source IP1, destination IP2&lt;/P&gt;&lt;P&gt;2nd filter ID 2: source IP2, destination IP1.&lt;/P&gt;&lt;P&gt;I define files for all 4 stages of capture.&lt;/P&gt;&lt;P&gt;To avoid problems I then use "debug dataplane packet-diag clear filter-marked-session all"&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;And start capture.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;However I don't get any PCAP files at all. And I know traffic is going through FW between these 2 hosts as I have an active session between those 2 IPs with increasing amount of bytes.&lt;/P&gt;&lt;P&gt;Any ideas if this is a bug or are my filters wrong?&lt;/P&gt;&lt;P&gt;how do you set filters for monitoring traffic between 2 IPs in both directions in all stages?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards, &lt;/P&gt;&lt;P&gt;Simon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2014 08:07:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9462#M6943</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-07-25T08:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: Packet capture filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9463#M6944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All sounds reasonable, except I've never used the command &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;"debug dataplane packet-diag clear filter-marked-session all"&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you dump out and share the output of "&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;debug dataplane packet-diag show setting" ?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2014 13:11:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9463#M6944</guid>
      <dc:creator>ajbool</dc:creator>
      <dc:date>2014-07-25T13:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Packet capture filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9464#M6945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh, there is one issue I tend to find...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have one filter, and then just go and change the IP addresses I tend to find that doesn't take effect.&amp;nbsp; So when chaining the filter in the WebUI I laboriously delete all filter enteris, disable filter and then create new filter entries and re-enable filtering...&amp;nbsp; A bit of a pain in the ass &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&amp;nbsp; I'm starting to use the CLI for this now to make this a little more efficient...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2014 13:16:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9464#M6945</guid>
      <dc:creator>ajbool</dc:creator>
      <dc:date>2014-07-25T13:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: Packet capture filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9465#M6946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Santonic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Try command "debug software restart vardata." let me know if that fix the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;You will have to reconfigure capture/filter after that.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2014 14:39:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9465#M6946</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-25T14:39:10Z</dc:date>
    </item>
    <item>
      <title>Re: Packet capture filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9466#M6947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Santonic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Ajbool said before, could you please run the CLI command &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;multiple&amp;nbsp; times &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;with 5 &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;seconds&lt;/SPAN&gt; interval)&lt;/SPAN&gt;: &amp;gt; &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;debug data-plane packet-&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;diag&lt;/SPAN&gt; show setting ----&amp;nbsp; and compare "captured byte" counts. If the byte count is increasing, it means the traffic is getting matched &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;with&lt;/SPAN&gt; the filter. In that situation, you need to restart the &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;vardata&lt;/SPAN&gt;-receiver process &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;responsible to capture packet). CLI command: &amp;gt; debug software &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;restart&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;vardata&lt;/SPAN&gt;-receiver.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="packet-filter.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14685_packet-filter.jpg" style="height: 429px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2014 15:10:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9466#M6947</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-25T15:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Packet capture filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9467#M6948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@ajbool&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, i've encountered same problem about captures containing unwanted traffic after changing filter settings. That's where the command I mentioned comes in handy: it unmarks all sessions which were marked by previous packet capture filter. So I use it between changing filters.&lt;/P&gt;&lt;P&gt;I found it here: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-2859"&gt;Packet Capture Contains Traffic not Defined in Filter&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you about other tips too. I'll try that when I'm having issues again.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2014 08:16:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9467#M6948</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2014-07-28T08:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: Packet capture filters</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9468#M6949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ar, OK, it seems that command will help me out.&amp;nbsp; Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2014 10:19:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-filters/m-p/9468#M6949</guid>
      <dc:creator>ajbool</dc:creator>
      <dc:date>2014-07-28T10:19:01Z</dc:date>
    </item>
  </channel>
</rss>

