broadleyn wrote:
Must have :
So important, I'm listing it before my numbered items below : TCPDUMP support. I miss this basic feature nearly every day since our switch to Palo Alto. The web-based set up of background packet filters across fw, rx, tx and drop profiles is so tedious, I die inside each time I'm forced to use it. I now tcpdump from our F5's far more often because it's easier to troubleshoot using this industry standard and well-understood tool.
I miss tcpdump as well. My eyes lit up when I saw a reference to tcpdump in the PANOS 5.0 documentation and after loading up 5.0 on a test box sure enough the tcpdump command was now present. Unfortunately it can only capture traffic on the management interface NIC and doesn't work with the data plane interfaces.
... View more