Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Capture packets on a Palo Alto Networks firewall

From Tech-Wiki


Capture dataplane packets on a Palo Alto Networks firewall with a tightly scoped PAN-OS packet filter.

ⓘ
Validation status
Reviewed against the current PAN-OS packet-capture documentation and PAN-OS 11.x/12.x CLI command hierarchy on 27 September 2026.
!
Packet capture can affect firewall performance
Palo Alto Networks states that dataplane packet capture can be CPU intensive and degrade firewall performance. Scope filters carefully, set packet limits where possible, stop the capture immediately after reproducing the issue and remove the diagnostic configuration afterwards.
!
Captures can contain sensitive information
PCAP files can contain internal addresses, credentials, session identifiers and application data. Handle captures according to the sensitivity of the traffic being inspected.

Start clean

Clear previous packet-diagnostic settings before starting a new controlled capture:

>_Clear existing packet-diagnostic configuration
debug dataplane packet-diag clear all

Configure a narrow filter

This example captures TCP/443 traffic from one documentation address to another.

>_Configure the packet filter
debug dataplane packet-diag set filter match source 192.0.2.10 destination 198.51.100.20 destination-port 443 protocol 6
debug dataplane packet-diag set filter on

Replace the documentation addresses and port with the exact flow being investigated.

Configure capture stages

PAN-OS supports captures at multiple packet-processing stages. Using the same flow at several stages can help identify where a packet is changed or dropped.

>_Configure bounded capture files
debug dataplane packet-diag set capture stage receive file receive.pcap packet-count 1000
debug dataplane packet-diag set capture stage firewall file firewall.pcap packet-count 1000
debug dataplane packet-diag set capture stage drop file drop.pcap packet-count 1000
debug dataplane packet-diag set capture stage transmit file transmit.pcap packet-count 1000

Run the capture

>_Start and verify packet capture
debug dataplane packet-diag set capture on
debug dataplane packet-diag show setting

Reproduce the issue for the shortest practical period, then stop both capture and filter:

>_Stop packet capture
debug dataplane packet-diag set capture off
debug dataplane packet-diag set filter off

Inspect the capture

A capture file can be viewed from the CLI:

>_View a capture file
view-pcap filter-pcap firewall.pcap

For deeper analysis, export the required PCAP files through the approved administrative transfer method and analyse them in Wireshark.

Hardware offload and difficult captures

Palo Alto Networks notes that hardware offload may need to be disabled for some dataplane captures so that the required traffic is visible.

Do not disable hardware offload routinely. Use the vendor procedure for the target platform and restore the normal state when troubleshooting is complete.

For performance or packet-order investigations, Palo Alto Networks recommends considering an external capture on a neighbouring switch/SPAN point because an on-box capture itself consumes firewall resources.

Clean up

>_Remove packet-diagnostic settings
debug dataplane packet-diag clear all

Official references

See also