<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: commands to  debug traffic between two host using Palo alto firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/commands-to-debug-traffic-between-two-host-using-palo-alto/m-p/337975#M85043</link>
    <description>&lt;P&gt;Thanks a Lot.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jul 2020 01:44:22 GMT</pubDate>
    <dc:creator>Gabriel.Nigro</dc:creator>
    <dc:date>2020-07-13T01:44:22Z</dc:date>
    <item>
      <title>commands to  debug traffic between two host using Palo alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commands-to-debug-traffic-between-two-host-using-palo-alto/m-p/48503#M35709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can some one help with documentation with running debug&amp;nbsp; commands on palo alto firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example syntax to monitor traffic between two particular host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for help in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 May 2014 15:52:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commands-to-debug-traffic-between-two-host-using-palo-alto/m-p/48503#M35709</guid>
      <dc:creator>fatboy1607</dc:creator>
      <dc:date>2014-05-14T15:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: commands to  debug traffic between two host using Palo alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commands-to-debug-traffic-between-two-host-using-palo-alto/m-p/48504#M35710</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mandar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use following document for detailed description :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2313"&gt;How to Run a Packet Capture&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also run "show session all filter source &amp;lt;ip&amp;gt; destination &amp;lt;ip&amp;gt;" to view the traffic flow through the device. You can narrow it down to zones, ports and application. HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 May 2014 15:55:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commands-to-debug-traffic-between-two-host-using-palo-alto/m-p/48504#M35710</guid>
      <dc:creator>ssharma</dc:creator>
      <dc:date>2014-05-14T15:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: commands to  debug traffic between two host using Palo alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commands-to-debug-traffic-between-two-host-using-palo-alto/m-p/48505#M35711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;something more granular but be sure to confirm filter is enabled and to clear the debugging when you're done. This can be intrusive debugging so doing it carefully is highly recommended&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1506"&gt;Packet Capture, Debug Flow-basic and Counter Commands&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 May 2014 15:56:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commands-to-debug-traffic-between-two-host-using-palo-alto/m-p/48505#M35711</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2014-05-14T15:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: commands to  debug traffic between two host using Palo alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commands-to-debug-traffic-between-two-host-using-palo-alto/m-p/48506#M35712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Below are the steps that i would take to troubleshoot but be sure to turn off all the debugging after you are done. Since this is CPU intensive and make sure setup filter on traffic that you are interested in debugging.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Hope this helps.&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;1. Need to setup the filters for the traffic we are interested in. To do this, execute the following steps:&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;Navigate to Monitor--Packet Capture&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;Click 'Manage Filters'&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;Set Filter ID 1 to be the source IP and destination IP of traffic you feel is affected ( leave all other fields blank )&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;Set Filter ID 2 to be the exact inverse of what you did in step 3 (destination IP in source field, Source IP in destination field)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;2. Setup up the captures&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;Create and name the file stage for a packet capture on all the stages (receive, transmit, firewall and drop)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;3. setup the flow basic&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;debug dataplane packet-diag set log feature flow basic&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;debug dataplane packet-diag set log feature ctd basic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;4. Clear old logs flow basic logs&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;debug dataplane packet-diag clear log log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;5. Enable filters, captures and logs&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;debug dataplane packet-diag set filter on&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;debug dataplane packet-diag set capture on&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;debug dataplane packet-diag set log on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;6. open 3 CLI windows&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;on 1 run the following command to look at the counter ( make sure it run this command once before running the traffic)&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;show counter global filter packet-filter yes delta yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;on the 2nd window run the following command to look at he sessions&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;show session all filter source &amp;lt;ip address&amp;gt; destination &amp;lt;ip address&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;On the 3rd window run the tail for the flow basic&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;tail follow yes dp-log pan_task_*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;7. Now run the test&amp;nbsp; while it fails .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;8. Turn off all the debugging that was enabled&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;debug dataplane packet-diag set log off&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;debug dataplane packet-diag set filter off&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;debug dataplane packet-diag set capture off&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;9. Aggregate the flow basic logs&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;CLI command (be sure to do this AFTER disabling the data plane debug logging such as flow basic):&lt;/P&gt;&lt;P style="font-family: Calibri; font-size: 11.0pt;"&gt;debug dataplane packet-diag aggregate-logs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 May 2014 20:12:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commands-to-debug-traffic-between-two-host-using-palo-alto/m-p/48506#M35712</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2014-05-15T20:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: commands to  debug traffic between two host using Palo alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commands-to-debug-traffic-between-two-host-using-palo-alto/m-p/48507#M35713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Either 'show session all filer source x.x.x.x destination y.y.y.y' or set the filter in the PCAP should give you the ability of checking the traffic running between two specific hosts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 May 2014 07:14:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commands-to-debug-traffic-between-two-host-using-palo-alto/m-p/48507#M35713</guid>
      <dc:creator>mizhou</dc:creator>
      <dc:date>2014-05-21T07:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: commands to  debug traffic between two host using Palo alto firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/commands-to-debug-traffic-between-two-host-using-palo-alto/m-p/337975#M85043</link>
      <description>&lt;P&gt;Thanks a Lot.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 01:44:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/commands-to-debug-traffic-between-two-host-using-palo-alto/m-p/337975#M85043</guid>
      <dc:creator>Gabriel.Nigro</dc:creator>
      <dc:date>2020-07-13T01:44:22Z</dc:date>
    </item>
  </channel>
</rss>

