Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

PA Packet capture

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PA Packet capture

L4 Transporter

Is there anyway to get bi-directional data in a single packet capture on the PA ?  Some of mine seem like it splits the traffic into tranmissions on one, drop on another and recieve on yet another. Can those all be combined?

2 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

@jdprovine,

You can merge the PCAPs once you've finished collectiong them, however the stage is what the firewall is actually capturing so it isn't able to take a full capture of everything. 

* Drops: Records packets that are dropped due to an error. 

* Firewall: Captures when the device is processing packets.

* Receive: Packets that are recieved by the device. 

* Transmit: Packets sent from the source. 

 

If you utilize WireShark you can actually merge all of these chronologically to essentially get what you are looking for in one large file. To do so simply open one of the PCAPs and select FileMerge select the other PCAP and then select whether you want to Prepend, Append, or Merge Chronologically. 

View solution in original post

L7 Applicator

If you enter the same filename for all four stages, I thought you will have everything in one file directly on the firewall...

View solution in original post

6 REPLIES 6

Cyber Elite
Cyber Elite

@jdprovine,

You can merge the PCAPs once you've finished collectiong them, however the stage is what the firewall is actually capturing so it isn't able to take a full capture of everything. 

* Drops: Records packets that are dropped due to an error. 

* Firewall: Captures when the device is processing packets.

* Receive: Packets that are recieved by the device. 

* Transmit: Packets sent from the source. 

 

If you utilize WireShark you can actually merge all of these chronologically to essentially get what you are looking for in one large file. To do so simply open one of the PCAPs and select FileMerge select the other PCAP and then select whether you want to Prepend, Append, or Merge Chronologically. 

L7 Applicator

If you enter the same filename for all four stages, I thought you will have everything in one file directly on the firewall...

@Remo,

Does...does that actually work? 

 

Wow that actually works. I've always just assumed that the file needs to be different for the different stages. This will save quite a bit of time throughout the week, thanks @Remo

a word of caution on @Remo's trick

 

The advantage is that you get everything in one file, but you may lose some visibility on which packets are missing from a stage and, if your capture is large: the pcaps roll over at 200mb, if you put 4 streams into one file, it will roll over much quicker

we do create a pcap.1, so your total size limit is 400mb of capture, but beware that if you put tx + rx + fw into a single file, you'll only be able to get +- 133mb of total traffic beforee you start losing the start of your capture

 

other than that: awesome trick!

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper @BPry @Remo

 

As always you have made it hard for me to pick the accepted solution because you all offer such great idea. Thanks!!

good news! you can select multiple 😜

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 2 accepted solutions
  • 5785 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!