<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PA random packet captures in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-random-packet-captures/m-p/10586#M7801</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've noticed that our 5020 is taking (what seems like)random packet captures.&amp;nbsp; I searched this forum about this, and have read that the PA does do packet captures if the traffic is identified as "unknown-tcp" and "insufficient-data".&amp;nbsp; The traffic I see that is generating pcaps seems random.&amp;nbsp; For example, there are pcaps for "ciscovpn", "apple-push-notifications", "kontiki", etc.&amp;nbsp; If I look into the "Log Details", these sessions are not hitting any Threat rules that might have caused a packet capture.&amp;nbsp; Also, CLI packet capturing(set application dump) is off, as well as the packet capture option in the GUI.&amp;nbsp; Anyone else experience this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Mar 2013 15:14:29 GMT</pubDate>
    <dc:creator>jambulo</dc:creator>
    <dc:date>2013-03-26T15:14:29Z</dc:date>
    <item>
      <title>PA random packet captures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-random-packet-captures/m-p/10586#M7801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've noticed that our 5020 is taking (what seems like)random packet captures.&amp;nbsp; I searched this forum about this, and have read that the PA does do packet captures if the traffic is identified as "unknown-tcp" and "insufficient-data".&amp;nbsp; The traffic I see that is generating pcaps seems random.&amp;nbsp; For example, there are pcaps for "ciscovpn", "apple-push-notifications", "kontiki", etc.&amp;nbsp; If I look into the "Log Details", these sessions are not hitting any Threat rules that might have caused a packet capture.&amp;nbsp; Also, CLI packet capturing(set application dump) is off, as well as the packet capture option in the GUI.&amp;nbsp; Anyone else experience this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 15:14:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-random-packet-captures/m-p/10586#M7801</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2013-03-26T15:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: PA random packet captures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-random-packet-captures/m-p/10587#M7802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So does it capture random packets with the expected ones or only random packets.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 18:32:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-random-packet-captures/m-p/10587#M7802</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-03-26T18:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: PA random packet captures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-random-packet-captures/m-p/10588#M7803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I tell it to capture packets, it'll capture the specified packets just fine.&amp;nbsp; But with packet capturing turned off, it's still capturing packets, and randomly it seems.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 21:04:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-random-packet-captures/m-p/10588#M7803</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2013-03-26T21:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: PA random packet captures</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-random-packet-captures/m-p/10589#M7804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Weird. Please open a case with support so that we can investigate the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 21:24:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-random-packet-captures/m-p/10589#M7804</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-03-26T21:24:50Z</dc:date>
    </item>
  </channel>
</rss>

