Capture traffic as is on the wire?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Capture traffic as is on the wire?

L1 Bithead

On a Palo Alto is there a way to take a packet capture on a specified interface and simply see everything as is on the wire?

 

For example on a Check Point I can do a tcp dump on a specified interface and the interface is basically put into promiscuous mode and I see traffic after firewall, after NAT, etc.  On my Palo's it seems I have to pick a stage for a capture and I can't find a way to simply see everything as is on the interface / wire level.

1 REPLY 1

Community Team Member

Hi @mjensen40400 ,

 

You are current.  You can get the PCAP for the different stages and merge them together to get the complete view.

The importance of the stages is to ensure you are able to verify if NAT is applied properly.  It also allows you to see if there's a difference between the packets sent out and received from both the client and server perspectives:

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClTJCA0

 

Don't get me wrong ... I totally understand how a tcpdump can be a very quick and easy way to look at the traffic.  You can do a tcpdump on the management interface at the moment:

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleECAS

 

There's also a feature request for this (FR# 947 - tcpdump style command for packet capture) so I would certainly recommend you to reach out to your local SE and have him add your vote to this request.  Share the word and have more customers add their vote.

 

Cheers !

-Kiwi.

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 2152 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!