PA random packet captures

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PA random packet captures

L4 Transporter

I've noticed that our 5020 is taking (what seems like)random packet captures.  I searched this forum about this, and have read that the PA does do packet captures if the traffic is identified as "unknown-tcp" and "insufficient-data".  The traffic I see that is generating pcaps seems random.  For example, there are pcaps for "ciscovpn", "apple-push-notifications", "kontiki", etc.  If I look into the "Log Details", these sessions are not hitting any Threat rules that might have caused a packet capture.  Also, CLI packet capturing(set application dump) is off, as well as the packet capture option in the GUI.  Anyone else experience this?

Thanks

3 REPLIES 3

L5 Sessionator

So does it capture random packets with the expected ones or only random packets.

When I tell it to capture packets, it'll capture the specified packets just fine.  But with packet capturing turned off, it's still capturing packets, and randomly it seems.

Weird. Please open a case with support so that we can investigate the issue.

  • 2133 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!