<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Interface ping logs are not  showing in traffic log in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/interface-ping-logs-are-not-showing-in-traffic-log/m-p/245082#M69882</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firewall interface configured with management profile where ICMP is enabled and i can ping the firewall ip. But we can't see any logs for ICMP in firewall .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How we can get this ?&lt;/P&gt;</description>
    <pubDate>Mon, 07 Jan 2019 08:27:57 GMT</pubDate>
    <dc:creator>gpsriram</dc:creator>
    <dc:date>2019-01-07T08:27:57Z</dc:date>
    <item>
      <title>Interface ping logs are not  showing in traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-ping-logs-are-not-showing-in-traffic-log/m-p/245082#M69882</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firewall interface configured with management profile where ICMP is enabled and i can ping the firewall ip. But we can't see any logs for ICMP in firewall .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How we can get this ?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 08:27:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-ping-logs-are-not-showing-in-traffic-log/m-p/245082#M69882</guid>
      <dc:creator>gpsriram</dc:creator>
      <dc:date>2019-01-07T08:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Interface ping logs are not  showing in traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-ping-logs-are-not-showing-in-traffic-log/m-p/245095#M69884</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98460"&gt;@gpsriram&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as I know ICMP is not an option in the interface management profile.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ping is the selectable option as shown in the screenshot :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ping_profile.jpg" style="width: 377px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18169i4B7679189253F050/image-dimensions/377x308?v=v2" width="377" height="308" role="button" title="ping_profile.jpg" alt="ping_profile.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Look for 'ping' application in your traffic log instead of icmp application ... + also make sure that the security rule which is being hit is actually being logged :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="traffic_log.jpg" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18170i1E7F083EEBDE3D65/image-size/medium?v=v2&amp;amp;px=400" role="button" title="traffic_log.jpg" alt="traffic_log.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 07 Jan 2019 09:57:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-ping-logs-are-not-showing-in-traffic-log/m-p/245095#M69884</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2019-01-07T09:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Interface ping logs are not  showing in traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-ping-logs-are-not-showing-in-traffic-log/m-p/245099#M69885</link>
      <description>&lt;P&gt;yes it displays as ping but only if you have a security policy that it matches with log enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can only see it in &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;screen shot as it's&amp;nbsp;hitting the rule "vdraad".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you are just relying on the management profile then it seems not to show in traffic log.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jan 2019 12:46:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-ping-logs-are-not-showing-in-traffic-log/m-p/245099#M69885</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-07T12:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Interface ping logs are not  showing in traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-ping-logs-are-not-showing-in-traffic-log/m-p/245322#M69926</link>
      <description>&lt;P&gt;Most probably because you don't have specific rule allowing this traffic, but rather relying on the default intra-zone rule, which doesn't log any traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even that you have interface management profile you still need a rule the policy to allow that traffic. It is common mistake to overlook this as in most of the cases the default intra-zone rule is already allowing this traffic. But default settings for the intra-zone rule is to NOT log the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is two ways to solve this:&lt;/P&gt;&lt;P&gt;- Create specific rule (same source and destination zone) for this traffic and enable the log option on this rule&lt;/P&gt;&lt;P&gt;- Override the default intra-zone rule and enable the logging.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note that the second option will log any other intra-zone traffic so, depending on your enviroment it migth generate lots of lots of unecessary logs&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 12:54:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-ping-logs-are-not-showing-in-traffic-log/m-p/245322#M69926</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2019-01-09T12:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: Interface ping logs are not  showing in traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/interface-ping-logs-are-not-showing-in-traffic-log/m-p/245323#M69927</link>
      <description>&lt;P&gt;Good point Mr Astardzhiev.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2019 12:58:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/interface-ping-logs-are-not-showing-in-traffic-log/m-p/245323#M69927</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-09T12:58:20Z</dc:date>
    </item>
  </channel>
</rss>

