PAN OS Packet Capture

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PAN OS Packet Capture

Not applicable

I know where and how to start a packet capture on the device.  I would like to know if the capture can be configured to capture only specific parameters (ie src ip, dst ip, src port, dst port).  I don't see those options on the web GUI.

2 REPLIES 2

Retired Member
Not applicable

Yes it is possible to apply filters on packet captures. In fact it is highly recommended as PAN packet-capture is meant as a debugging tool for specific traffic only and not for whole subnet capturing. From within Monitor tab > Packet Capture, there is a Filtering section. Click on Manage Filters. From there you can add up to 4 filters based on source/destination IP, source/destination port, interface or protocol. Be sure to also enable the 'Filtering' switch to ON.

-Richard

That manage filter did not look like a link or button so did not give it any thought to hover the mouse pointer over it.

Thanks that is what I was looking for.

  • 2127 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!