<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Transport of Decrypt Port Mirror traffic to a remote Switch/Server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/transport-of-decrypt-port-mirror-traffic-to-a-remote-switch/m-p/391459#M90782</link>
    <description>&lt;P&gt;this may be a question for cisco &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The decrypt port simply spits out packets as they go through the firewall so they're not routable or switchable (no MAC information)&lt;/P&gt;&lt;P&gt;An RSPAN still relies on capturing 'legitimate' traffic on a access/trunk port and forwarding the utput to a remote output&lt;/P&gt;</description>
    <pubDate>Tue, 16 Mar 2021 13:47:05 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2021-03-16T13:47:05Z</dc:date>
    <item>
      <title>Transport of Decrypt Port Mirror traffic to a remote Switch/Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/transport-of-decrypt-port-mirror-traffic-to-a-remote-switch/m-p/391323#M90767</link>
      <description>&lt;P&gt;We've been trying to redirect the decrypted port mirror traffic to a remote sever in the network.&lt;/P&gt;&lt;P&gt;If we plug a notebook into the decrytp port mirror of Palo Alto, we see all the decrypted traffic in Wireshark.&lt;/P&gt;&lt;P&gt;So, we tried to connect PA port into a switch and use Cisco RSPAN to send the traffic to our remote Server. It just doesn't work.&lt;/P&gt;&lt;P&gt;I may be failing on basic concepts here. Can anyone help me by saying how to make it work or, if so, why it should never work like this?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA[decryp.port.mirror] --&amp;gt; Notebook: OK&lt;/P&gt;&lt;P&gt;PA[decryp.port.mirror] --&amp;gt; SW1..n[RSPAN] --&amp;gt; Server: Not OK!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 18:10:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/transport-of-decrypt-port-mirror-traffic-to-a-remote-switch/m-p/391323#M90767</guid>
      <dc:creator>LeonardoMachado</dc:creator>
      <dc:date>2021-03-15T18:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Transport of Decrypt Port Mirror traffic to a remote Switch/Server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/transport-of-decrypt-port-mirror-traffic-to-a-remote-switch/m-p/391459#M90782</link>
      <description>&lt;P&gt;this may be a question for cisco &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The decrypt port simply spits out packets as they go through the firewall so they're not routable or switchable (no MAC information)&lt;/P&gt;&lt;P&gt;An RSPAN still relies on capturing 'legitimate' traffic on a access/trunk port and forwarding the utput to a remote output&lt;/P&gt;</description>
      <pubDate>Tue, 16 Mar 2021 13:47:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/transport-of-decrypt-port-mirror-traffic-to-a-remote-switch/m-p/391459#M90782</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-03-16T13:47:05Z</dc:date>
    </item>
  </channel>
</rss>

