<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Capture traffic as is on the wire? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/capture-traffic-as-is-on-the-wire/m-p/397443#M91480</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131513"&gt;@mjensen40400&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are current.&amp;nbsp; You can get the PCAP for the different stages and merge them together to get the complete view.&lt;/P&gt;
&lt;P&gt;The importance of the stages is to ensure you are able to verify if NAT is applied properly.&amp;nbsp; It also allows you to see if there's a difference between the packets sent out and received from both the client and server perspectives:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Don't get me wrong ... I totally understand how a tcpdump can be a very quick and easy way to look at the traffic.&amp;nbsp; You can do a tcpdump on the management interface at the moment:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's also a feature request for this (FR# 947 -&amp;nbsp;tcpdump style command for packet capture) so I would certainly recommend you to reach out to your local SE and have him add your vote to this request.&amp;nbsp; Share the word and have more customers add their vote.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Tue, 13 Apr 2021 08:42:53 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2021-04-13T08:42:53Z</dc:date>
    <item>
      <title>Capture traffic as is on the wire?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/capture-traffic-as-is-on-the-wire/m-p/397216#M91464</link>
      <description>&lt;P&gt;On a Palo Alto is there a way to take a packet capture on a specified interface and simply see everything as is on the wire?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example on a Check Point I can do a tcp dump on a specified interface and the interface is basically put into promiscuous mode and I see traffic after firewall, after NAT, etc.&amp;nbsp; On my Palo's it seems I have to pick a stage for a capture and I can't find a way to simply see everything as is on the interface / wire level.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 14:25:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/capture-traffic-as-is-on-the-wire/m-p/397216#M91464</guid>
      <dc:creator>mjensen40400</dc:creator>
      <dc:date>2021-04-12T14:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Capture traffic as is on the wire?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/capture-traffic-as-is-on-the-wire/m-p/397443#M91480</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131513"&gt;@mjensen40400&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are current.&amp;nbsp; You can get the PCAP for the different stages and merge them together to get the complete view.&lt;/P&gt;
&lt;P&gt;The importance of the stages is to ensure you are able to verify if NAT is applied properly.&amp;nbsp; It also allows you to see if there's a difference between the packets sent out and received from both the client and server perspectives:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Don't get me wrong ... I totally understand how a tcpdump can be a very quick and easy way to look at the traffic.&amp;nbsp; You can do a tcpdump on the management interface at the moment:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's also a feature request for this (FR# 947 -&amp;nbsp;tcpdump style command for packet capture) so I would certainly recommend you to reach out to your local SE and have him add your vote to this request.&amp;nbsp; Share the word and have more customers add their vote.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 13 Apr 2021 08:42:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/capture-traffic-as-is-on-the-wire/m-p/397443#M91480</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2021-04-13T08:42:53Z</dc:date>
    </item>
  </channel>
</rss>

