threat packet captures impact on cpu

L2 Linker

threat packet captures impact on cpu


I would like to enable some packet captures on certain threats and was wondering if anyone has tested if there is an impact on the mgmt plane cpu when enabling extra pcaps?

I know enabling packet capture has an impact on cpu. however I would think the impact woudl be mainly(or exclusively) on the data plane cpu;

reason I ask is I currently have a pa-2000 series on which I may need to enable a few extra packet captures of threats over an extended period of time.

the pa-2000 has an astmatic hamster for a mgmt cpu and is already overloaded.

If anyone has tested this or a definitive answer I would appreciate it. if not I'll test this out myself however I can't do it right now due to currently not having access to a lab environment to test this.






L7 Applicator

Re: threat packet captures impact on cpu


The PA-2000's share the CPU between the data plane and management plane. While it would take a small hit, I think your biggest worry might be disk space for the pcaps.


You can always enable it during off peak hours and test.



Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!