Packet Capture Mgmt Interface?

Reply
Highlighted
Not applicable

Packet Capture Mgmt Interface?

Is it possible to packet capture traffic on the management interface using the Monitor->Packet Capture feature?

Mike


Accepted Solutions
Highlighted
L5 Sessionator

Prior to 5.0.x captures on management interface was not supported.

However with 5.0.x it was introduced.

Below is the doc that explains on how this can be achieved

https://live.paloaltonetworks.com/docs/DOC-4595

Hope this helps.
Thanks

Numan

View solution in original post


All Replies
Highlighted
L7 Applicator

Hi,

We cannot capture the traffic directly on the management interface but there is a way to capture the management traffic on the device using "service routes" . Service routes are used to send/receive the management traffic of the device from one of the dataplane interfaces instead of the mgmt interface. You configure this option from the device-->setup-->services-->service configuration. Once you do this, the mgmt traffic will take the path of the configured interface rather than the mgmt interface. Now you can capture this interface for analyzing the mgmt traffic.


Please follow below mentioned discussion for more information.

https://live.paloaltonetworks.com/message/4565#4565

https://live.paloaltonetworks.com/message/4496#4496

https://live.paloaltonetworks.com/message/11542#11542

https://live.paloaltonetworks.com/message/17468#17468

Hope it helps.

Thanks

Highlighted
Not applicable

Thanks for the info. I think it will be better for us to just configure a mirror port on a switch and capture traffic that way.

Mike

L7 Applicator

Hi Mike,

Yes you are correct, you can do port mirroring on the connected S/W also.

Thanks

Highlighted
L5 Sessionator

We can run a packet capture on the Management interface, using TCPDUMP commands. This is supported from 5.0 onwards.

The below doc explains the same:

https://live.paloaltonetworks.com/docs/DOC-3362

Hope that answers your question.

BR,

Karthik RP

Highlighted
L5 Sessionator

Prior to 5.0.x captures on management interface was not supported.

However with 5.0.x it was introduced.

Below is the doc that explains on how this can be achieved

https://live.paloaltonetworks.com/docs/DOC-4595

Hope this helps.
Thanks

Numan

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!