Capture packets on a Palo Alto Networks firewall
More actions
Capture dataplane packets on a Palo Alto Networks firewall with a tightly scoped PAN-OS packet filter.
Start clean
Clear previous packet-diagnostic settings before starting a new controlled capture:
debug dataplane packet-diag clear all
Configure a narrow filter
This example captures TCP/443 traffic from one documentation address to another.
debug dataplane packet-diag set filter match source 192.0.2.10 destination 198.51.100.20 destination-port 443 protocol 6 debug dataplane packet-diag set filter on
Replace the documentation addresses and port with the exact flow being investigated.
Configure capture stages
PAN-OS supports captures at multiple packet-processing stages. Using the same flow at several stages can help identify where a packet is changed or dropped.
debug dataplane packet-diag set capture stage receive file receive.pcap packet-count 1000 debug dataplane packet-diag set capture stage firewall file firewall.pcap packet-count 1000 debug dataplane packet-diag set capture stage drop file drop.pcap packet-count 1000 debug dataplane packet-diag set capture stage transmit file transmit.pcap packet-count 1000
Run the capture
debug dataplane packet-diag set capture on debug dataplane packet-diag show setting
Reproduce the issue for the shortest practical period, then stop both capture and filter:
debug dataplane packet-diag set capture off debug dataplane packet-diag set filter off
Inspect the capture
A capture file can be viewed from the CLI:
view-pcap filter-pcap firewall.pcap
For deeper analysis, export the required PCAP files through the approved administrative transfer method and analyse them in Wireshark.
Hardware offload and difficult captures
Palo Alto Networks notes that hardware offload may need to be disabled for some dataplane captures so that the required traffic is visible.
Do not disable hardware offload routinely. Use the vendor procedure for the target platform and restore the normal state when troubleshooting is complete.
For performance or packet-order investigations, Palo Alto Networks recommends considering an external capture on a neighbouring switch/SPAN point because an on-box capture itself consumes firewall resources.
Clean up
debug dataplane packet-diag clear all