Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Take PCAP from the mgmt interface using the UI

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Take PCAP from the mgmt interface using the UI

L3 Networker

Hi All,

 

Is there a particular reason why this option is only available from the CLI?

 

Thanks,

Myky

1 accepted solution

Accepted Solutions

L4 Transporter

@myky I comes to the Palo Alto architecture - the Mgmt interface is attached to the management plane, which is linux based and you can run tcpdump. All data interfaces are part of the firewall Data Plane which does its own separate packet processing.

View solution in original post

8 REPLIES 8

L4 Transporter

@myky I comes to the Palo Alto architecture - the Mgmt interface is attached to the management plane, which is linux based and you can run tcpdump. All data interfaces are part of the firewall Data Plane which does its own separate packet processing.

@BatD  sounds like a reasonable explanation. Would be nice to have this feature integrated with UI. 

I usually have to keep a cheat list like this:

tcpdump filter "dst 10.10.20.6 or src 10.10.20.6"

view-pcap mgmt-pcap mgmt.pcap

view-pcap no-dns-lookup yes no-port-lookup yes mgmt-pcap mgmt.pcap 


 

@craigomatic I prefer to upload the file using SCP option. It is better to view it in the .pcap file

Definitely more readable in WireShark for sure. If you have that option of accessing an scp server ... sometimes that's not available in my experience!

@craigomatic  that is one of the reasons why l started this topic. Another thing with tcpdump, it is good for the basic connectivity check but for instance, if you would like to see RADIUS Access-Accept reply, in particular check for the attributes, tcpdump won't help((

If it's sent in clear text, with verbose commands and x offsets you should be able to see the packets. I've been able to grab ldap credentials on 389 like that. Not sure about radius. You have a whole other set of troubleshooting commands with auth, like below:

 

test authentication authentication-profile "CorpLDAP" username user password

 

Then you have to follow the authd.log:

tail follow yes mp-log authd.log

Thanks @craigomatic, very useful info 

  • 1 accepted solution
  • 7953 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!