<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet capture drop stage shows production traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396887#M91420</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In the drop logs, what is the reason it gives for the drop traffic?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 09 Apr 2021 14:51:38 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2021-04-09T14:51:38Z</dc:date>
    <item>
      <title>Packet capture drop stage shows production traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396675#M91397</link>
      <description>&lt;P&gt;I have been troubleshooting a intermittent issue where a device that sits behind my Palo Alto running 10.0.0.3 is frequently losing it's connection for UDP port 2156 traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today I ran a packet capture on the PA using the "drop stage" while the connectivity was lost and there was my missing traffic, right there in that capture.&lt;/P&gt;&lt;P&gt;When connectivity restored itself I ran the "drop stage" capture again and the interesting traffic was no longer present.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I investigate further to determine the reason why this traffic is getting dropped by the firewall?&amp;nbsp; When I look in the monitor &amp;gt; traffic logs I do not see this traffic as being dropped.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Apr 2021 20:50:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396675#M91397</guid>
      <dc:creator>mjensen40400</dc:creator>
      <dc:date>2021-04-08T20:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Packet capture drop stage shows production traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396699#M91401</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In the policy, make sure you are logging the traffic. Also when it cones to UDP traffic, the session stays open so it might not show in the traffic logs immediately. I would suggest checking the Session Browser as that is showing all active sessions and is better for looking at UDP traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However the traffic logs should show why the session ended and the policy that allowed/blocked the traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 08 Apr 2021 21:44:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396699#M91401</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-04-08T21:44:24Z</dc:date>
    </item>
    <item>
      <title>Re: Packet capture drop stage shows production traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396840#M91413</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131513"&gt;@mjensen40400&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try to check the global counters as described here - &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS" target="_blank"&gt;How to check global counters for a specific source and destinat... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;BR /&gt;- Set the same filter you have set for the packet capture&lt;/P&gt;&lt;P&gt;- Run the command &amp;gt;show counter global filter packet-filter yes delta yes (note that with the option delta the output will show only the difference between last and previous execution of the show command. )&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 11:32:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396840#M91413</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-04-09T11:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Packet capture drop stage shows production traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396851#M91414</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran a debug:&lt;/P&gt;&lt;PRE&gt;&amp;gt; debug dataplane packet-diag set log feature flow basic &lt;BR /&gt;&amp;gt; debug dataplane packet-diag set log on &lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;PRE&gt;debug dataplane packet-diag aggregate-logs
packet-diag.log is aggregated&lt;BR /&gt;&lt;BR /&gt;but I am not able to view the packet-diag.log which probably contains my answers.&lt;BR /&gt;Do you know how I can view the contents of the .log?&lt;/PRE&gt;</description>
      <pubDate>Fri, 09 Apr 2021 13:00:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396851#M91414</guid>
      <dc:creator>mjensen40400</dc:creator>
      <dc:date>2021-04-09T13:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Packet capture drop stage shows production traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396876#M91418</link>
      <description>&lt;P&gt;What is messed up is when I look in traffic logs and query for the traffic in question logs come up from days ago and nothing current.&amp;nbsp; For example this morning I can only see traffic logs for the interesting traffic from April 5th!&lt;/P&gt;&lt;P&gt;The security policy rules are set to log.&lt;/P&gt;&lt;P&gt;I know for sure this traffic has successfully passed through the firewall since the 5th as this problem is intermitent and the traffic flow does work sometimes.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 14:17:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396876#M91418</guid>
      <dc:creator>mjensen40400</dc:creator>
      <dc:date>2021-04-09T14:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Packet capture drop stage shows production traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396887#M91420</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In the drop logs, what is the reason it gives for the drop traffic?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 14:51:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396887#M91420</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-04-09T14:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: Packet capture drop stage shows production traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396984#M91441</link>
      <description>&lt;P&gt;Using the global counters method I discovered the drop reason is due to arp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using the "show arp all" command I was able to determine that the firewall has a "incomplete" arp entry for it's default gateway during times the traffic stops and it has a actual full entry when traffic is flowing as it should.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have a static source NAT and I followed kb "FIREWALL IS DROPPING PACKETS FROM LAN FOR NO ARP"&amp;nbsp;@&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cmm8CAC&amp;amp;lang=en_US%E2%80%A9" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cmm8CAC&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My static NAT was a host IP without a netmask so I put a /32 at the end of it and that didn't make a difference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 19:00:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-capture-drop-stage-shows-production-traffic/m-p/396984#M91441</guid>
      <dc:creator>mjensen40400</dc:creator>
      <dc:date>2021-04-09T19:00:55Z</dc:date>
    </item>
  </channel>
</rss>

