{"id":585,"date":"2015-02-18T13:12:37","date_gmt":"2015-02-18T19:12:37","guid":{"rendered":"http:\/\/www.echorequest.com\/?p=585"},"modified":"2015-02-18T13:14:21","modified_gmt":"2015-02-18T19:14:21","slug":"palo-alto-basic-troubleshooting","status":"publish","type":"post","link":"https:\/\/www.echorequest.com\/?p=585","title":{"rendered":"Palo-Alto basic troubleshooting"},"content":{"rendered":"<p style=\"color: #141412;\">When troubleshooting network and security issues on many different devices I always miss some command options to do exactly what I want to do on the device I am currently working with. Therefore,\u00a0<strong>I list a few commands for the Palo Alto Networks firewalls to have a short reference for myself.<\/strong>\u00a0Maybe some other network professionals will find it useful.<\/p>\n<p style=\"color: #141412;\">However, since I am almost always using the GUI\u00a0<strong>this short reference only lists commands that are useful for the console while\u00a0<em>not<\/em>\u00a0present in the GUI<\/strong>.<span id=\"more-1011\"><\/span><\/p>\n<p style=\"color: #141412;\">This blog post will be a living document. Whenever I use some \u201cnew\u201d commands for troubleshooting issues, I will update it.\u00a0<strong>If there are any useful commands missing, please send me a comment!<\/strong><\/p>\n<p style=\"color: #141412;\">For a complete list of all CLI commands, use the\u00a0<a style=\"color: #bc360a;\" href=\"https:\/\/live.paloaltonetworks.com\/community\/documentation\" target=\"_blank\">CLI Reference Guides from PAN<\/a>. Or use the official\u00a0<a style=\"color: #bc360a;\" href=\"https:\/\/live.paloaltonetworks.com\/docs\/DOC-4254\" target=\"_blank\">Quick Reference Guide: Helpful Commands<\/a>\u00a0PDF.<\/p>\n<h2 style=\"color: #141412;\">Standard Show Commands<\/h2>\n<p style=\"color: #141412;\">The following commands are really the basics and need no further description. I list them just as a reference:<\/p>\n<div id=\"crayon-54e4e27dbe574385508577\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe574385508577-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe574385508577-2\">2<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe574385508577-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe574385508577-4\">4<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe574385508577-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe574385508577-6\">6<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe574385508577-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe574385508577-8\">8<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe574385508577-9\">9<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe574385508577-10\">10<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe574385508577-11\">11<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe574385508577-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show system info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\/\/shows the uptime of the device<\/div>\n<div id=\"crayon-54e4e27dbe574385508577-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">show session info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 \/\/packet rate, # of sessions, fastpath active, etc.<\/div>\n<div id=\"crayon-54e4e27dbe574385508577-3\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show interface { all | name-of-the-interface }<\/div>\n<div id=\"crayon-54e4e27dbe574385508577-4\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">show routing route<\/div>\n<div id=\"crayon-54e4e27dbe574385508577-5\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show routing protocol<\/div>\n<div id=\"crayon-54e4e27dbe574385508577-6\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">show arp all<\/div>\n<div id=\"crayon-54e4e27dbe574385508577-7\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show mac all<\/div>\n<div id=\"crayon-54e4e27dbe574385508577-8\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">show jobs all<\/div>\n<div id=\"crayon-54e4e27dbe574385508577-9\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show jobs id &lt;id&gt;<\/div>\n<div id=\"crayon-54e4e27dbe574385508577-10\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">show system resource follow\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\/\/CPU usage and processes<\/div>\n<div id=\"crayon-54e4e27dbe574385508577-11\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">debug software restart &lt;service&gt;\u00a0\u00a0 \/\/Restart a certain process<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">\u00a0<!--more--><\/p>\n<h2 style=\"color: #141412;\">Find<\/h2>\n<p style=\"color: #141412;\">Since PAN-OS 6.0, the \u201cfind\u201d command helps searching for the needed command in case you do not fully know the whole set of commands. With \u201cfind command\u201d, all possible commands are displayed. With \u201cfind command keyword xyz\u201d, all commands containing \u201cxyz\u201d are shown.<\/p>\n<div id=\"crayon-54e4e27dbe589984228672\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe589984228672-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe589984228672-2\">2<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe589984228672-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">find command<\/div>\n<div id=\"crayon-54e4e27dbe589984228672-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">find command keyword &lt;word-to-search-for&gt;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">Ping, Traceroute, and DNS<\/h2>\n<p style=\"color: #141412;\">A standard\u00a0<strong>ping command<\/strong>\u00a0looks like that:<\/p>\n<div id=\"crayon-54e4e27dbe594243730223\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe594243730223-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe594243730223-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">ping host 8.8.8.8<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">Note that this ping request is issued from the management interface! To use a data interface as the source, the option\u00a0<span id=\"crayon-54e4e27dbe59e853345206\" class=\"crayon-syntax crayon-syntax-inline  crayon-theme-classic crayon-theme-classic-inline crayon-font-monaco\"><span class=\"crayon-pre crayon-code\" style=\"color: #000000;\">source &lt;ip-address&gt;<\/span><\/span>\u00a0 can be used. To use IPv6, the option is\u00a0<span id=\"crayon-54e4e27dbe5a8434746682\" class=\"crayon-syntax crayon-syntax-inline  crayon-theme-classic crayon-theme-classic-inline crayon-font-monaco\"><span class=\"crayon-pre crayon-code\" style=\"color: #000000;\">inet6 yes<\/span><\/span>\u00a0. For example:<\/p>\n<div id=\"crayon-54e4e27dbe5b2760990625\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe5b2760990625-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe5b2760990625-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">ping inet6 yes source 2003:51:6012:120::1 host 2a00:1450:4008:800::1017<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">A\u00a0<strong>traceroute command<\/strong>\u00a0looks like that:<\/p>\n<div id=\"crayon-54e4e27dbe5bc636658535\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe5bc636658535-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe5bc636658535-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">traceroute host 8.8.8.8<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">The\u00a0<span id=\"crayon-54e4e27dbe5c6928450797\" class=\"crayon-syntax crayon-syntax-inline  crayon-theme-classic crayon-theme-classic-inline crayon-font-monaco\"><span class=\"crayon-pre crayon-code\" style=\"color: #000000;\">source &lt;ip-address&gt;<\/span><\/span>\u00a0 can be used to specify the outgoing interface. However, for IPv6, the option is dissimilar to the ping command:\u00a0<span id=\"crayon-54e4e27dbe5d0668037730\" class=\"crayon-syntax crayon-syntax-inline  crayon-theme-classic crayon-theme-classic-inline crayon-font-monaco\"><span class=\"crayon-pre crayon-code\" style=\"color: #000000;\">ipv6 yes<\/span><\/span>\u00a0.<\/p>\n<p style=\"color: #141412;\">To\u00a0<strong>resolve DNS names<\/strong>, e.g., to test the DNS server that is configured on the management interface, simply ping a name:<\/p>\n<div id=\"crayon-54e4e27dbe5da294995766\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe5da294995766-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe5da294995766-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">ping host ip.webernetz.net<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">Test<\/h2>\n<p style=\"color: #141412;\">The Palo offers some great test commands,\u00a0<strong>e.g., for testing a route-lookup, a VPN connection, or a security policy match<\/strong>. Use the question mark to find out more about the test commands. Here are some useful examples:<\/p>\n<div id=\"crayon-54e4e27dbe5e4869307354\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate crayon-wrapped\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim wrap\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe5e4869307354-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe5e4869307354-2\">2<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe5e4869307354-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe5e4869307354-4\">4<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe5e4869307354-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">test routing fib-lookup virtual-router default ip &lt;ip&gt;<\/div>\n<div id=\"crayon-54e4e27dbe5e4869307354-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">test vpn ipsec-sa tunnel &lt;value&gt;<\/div>\n<div id=\"crayon-54e4e27dbe5e4869307354-3\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">test security-policy-match ?<\/div>\n<div id=\"crayon-54e4e27dbe5e4869307354-4\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">test security-policy-match from trans-internet to pa-trust-server source 192.168.86.5 destination 192.168.120.2 protocol 6 application ssl destination-port 443<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">Viewing Management-Plane Logs<\/h2>\n<p style=\"color: #141412;\">In order to\u00a0<strong>view the debug log files<\/strong>, \u201cless\u201d or \u201ctail\u201d can be used. The keyword \u201cmp-log\u201d links to the management-plane logs (similar to \u201cdp-log\u201d for the dataplane-logs). The tail command can be used with \u201cfollow yes\u201d to have a live view of all logged messages. And as always: Use the question mark in order to display all possibilities.<\/p>\n<p style=\"color: #141412;\">Examples:<\/p>\n<div id=\"crayon-54e4e27dbe5ef746541135\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe5ef746541135-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe5ef746541135-2\">2<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe5ef746541135-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe5ef746541135-4\">4<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe5ef746541135-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">less mp-log ?<\/div>\n<div id=\"crayon-54e4e27dbe5ef746541135-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">less mp-log dnsproxyd.log<\/div>\n<div id=\"crayon-54e4e27dbe5ef746541135-3\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">tail follow yes mp-log dhcpd.log<\/div>\n<div id=\"crayon-54e4e27dbe5ef746541135-4\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">tail follow yes mp-log routed.log<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">Capturing Management Packets<\/h2>\n<p style=\"color: #141412;\">To view the traffic from the management port at least two console connections are needed. The first one executes the\u00a0<strong>tcpdump<\/strong>\u00a0command (with \u201csnaplen 0\u2033 for capturing the whole packet, and a filter, if desired),<\/p>\n<div id=\"crayon-54e4e27dbe5fa101409500\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe5fa101409500-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe5fa101409500-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">tcpdump snaplen 0 filter &#8220;port 53&#8221;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">while the second console\u00a0<strong>follows the live capture<\/strong>:<\/p>\n<div id=\"crayon-54e4e27dbe604735942416\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe604735942416-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe604735942416-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">view-pcap follow yes mgmt-pcap mgmt.pcap<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">Test traffic can be generated with a third console session, e.g.:<\/p>\n<div id=\"crayon-54e4e27dbe60e807562230\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe60e807562230-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe60e807562230-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">ping host webernetz.net<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">Later on, the\u00a0<strong>pcap file can be moved to another computer<\/strong>\u00a0with the following command:<\/p>\n<div id=\"crayon-54e4e27dbe618844672228\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe618844672228-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe618844672228-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">scp export mgmt-pcap from mgmt.pcap to &lt;username@host:path&gt;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">Alternatively,\u00a0<strong>tftp<\/strong>\u00a0can be used:<\/p>\n<div id=\"crayon-54e4e27dbe622851292144\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe622851292144-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe622851292144-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">tftp export mgmt-pcap from mgmt.pcap to &lt;host&gt;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">Live Viewing of Packet Captures<\/h2>\n<p style=\"color: #141412;\">When using the\u00a0<strong>Packet Capture<\/strong>\u00a0feature on the Palo Alto, the filter settings can easily be made from the GUI (Monitor -&gt; Packet Capture). These settings as well as the current size of the running packet capture files can be examined with:<\/p>\n<div id=\"crayon-54e4e27dbe62c722729750\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe62c722729750-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe62c722729750-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">debug dataplane packet-diag show setting<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">Now, the current capturing in follow mode can be viewed with:<\/p>\n<div id=\"crayon-54e4e27dbe637622700629\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe637622700629-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe637622700629-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">view-pcap follow yes filter-pcap<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">And for a really detailed analysis, the counters for these filtered packets can be viewed. This exactly reveals how many packets traversed which way, and so on.\u00a0<strong>With the \u201cdelta yes\u201d option, only the counter values since the last execution of this command are shown.<\/strong>\u00a0The \u201cpacket-filter yes\u201d option uses the packet filter from the GUI (Monitor -&gt; Packet Capture) to filter the counters:<\/p>\n<div id=\"crayon-54e4e27dbe641340634960\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe641340634960-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe641340634960-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show counter global filter packet-filter yes delta yes<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">For example, here are the delta counters after a few DNS lookups:<\/p>\n<div id=\"crayon-54e4e27dbe64b635928538\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num crayon-marked-num crayon-top crayon-bottom\" style=\"font-weight: inherit !important; color: #1561ac !important;\" data-line=\"crayon-54e4e27dbe64b635928538-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe64b635928538-2\">2<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe64b635928538-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe64b635928538-4\">4<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe64b635928538-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe64b635928538-6\">6<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe64b635928538-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe64b635928538-8\">8<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe64b635928538-9\">9<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe64b635928538-10\">10<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe64b635928538-11\">11<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe64b635928538-12\">12<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe64b635928538-13\">13<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe64b635928538-14\">14<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe64b635928538-15\">15<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe64b635928538-16\">16<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe64b635928538-17\">17<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe64b635928538-18\">18<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe64b635928538-19\">19<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe64b635928538-20\">20<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe64b635928538-21\">21<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe64b635928538-22\">22<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe64b635928538-23\">23<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe64b635928538-1\" class=\"crayon-line crayon-marked-line crayon-top crayon-bottom\" style=\"font-weight: inherit !important;\">weberjoh@fd-wv-fw02&gt; show counter global filter packet-filter yes delta yes<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\"><\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-3\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">Global counters:<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-4\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">Elapsed time since last sampling: 44.689 seconds<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-5\" class=\"crayon-line\" style=\"font-weight: inherit !important;\"><\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-6\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">name\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 value\u00a0\u00a0\u00a0\u00a0 rate severity\u00a0\u00a0category\u00a0\u00a0aspect\u00a0\u00a0\u00a0\u00a0description<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-7\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-8\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">pkt_sent\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a024\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0packet\u00a0\u00a0\u00a0\u00a0pktproc\u00a0\u00a0 Packets transmitted<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-9\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">pkt_outstanding\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0packet\u00a0\u00a0\u00a0\u00a0pktproc\u00a0\u00a0 Outstanding packet to be transmitted<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-10\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">pkt_alloc\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0120\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a02 info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0packet\u00a0\u00a0\u00a0\u00a0resource\u00a0\u00a0Packets allocated<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-11\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">session_allocated\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 19\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0session\u00a0\u00a0 resource\u00a0\u00a0Sessions allocated<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-12\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">session_installed\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 19\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0session\u00a0\u00a0 resource\u00a0\u00a0Sessions installed<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-13\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">flow_host_pkt_xmt\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0144\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a03 info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0flow\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0mgmt\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Packets transmitted to control plane<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-14\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">flow_host_service_allow\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0flow\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0mgmt\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Device management session allowed<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-15\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">appid_ident_by_dport_first\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a019\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0appid\u00a0\u00a0\u00a0\u00a0 pktproc\u00a0\u00a0 Application identified by L4 dport first<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-16\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">dfa_sw\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a048\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a01 info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0dfa\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 pktproc\u00a0\u00a0 The total number of dfa match using software<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-17\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">ctd_sml_vm_check_domain\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 24\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0ctd\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 pktproc\u00a0\u00a0 sml vm check domain<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-18\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">ctd_bloom_filter_nohit\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a024\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0ctd\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 pktproc\u00a0\u00a0 The number of no match for virus bloom filter<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-19\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">aho_sw\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a048\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a01 info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0aho\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 pktproc\u00a0\u00a0 The total usage of software for AHO<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-20\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">ctd_pkt_slowpath\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a048\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a01 info\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0ctd\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 pktproc\u00a0\u00a0 Packets processed by slowpath<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-21\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-22\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">Total counters shown: 13<\/div>\n<div id=\"crayon-54e4e27dbe64b635928538-23\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">Or, even more interesting,\u00a0<strong>filtered on \u201cdrop\u201d severity.<\/strong>\u00a0(Note the reasons on the right-hand side):<\/p>\n<div id=\"crayon-54e4e27dbe658096522871\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num crayon-marked-num crayon-top crayon-bottom\" style=\"font-weight: inherit !important; color: #1561ac !important;\" data-line=\"crayon-54e4e27dbe658096522871-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe658096522871-2\">2<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe658096522871-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe658096522871-4\">4<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe658096522871-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe658096522871-6\">6<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe658096522871-7\">7<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe658096522871-8\">8<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe658096522871-9\">9<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe658096522871-10\">10<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe658096522871-11\">11<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe658096522871-12\">12<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe658096522871-13\">13<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe658096522871-14\">14<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe658096522871-15\">15<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe658096522871-16\">16<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe658096522871-17\">17<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe658096522871-18\">18<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe658096522871-19\">19<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe658096522871-1\" class=\"crayon-line crayon-marked-line crayon-top crayon-bottom\" style=\"font-weight: inherit !important;\">weberjoh@fd-wv-fw02&gt; show counter global filter delta yes severity drop<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\"><\/div>\n<div id=\"crayon-54e4e27dbe658096522871-3\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">Global counters:<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-4\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">Elapsed time since last sampling: 166.755 seconds<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-5\" class=\"crayon-line\" style=\"font-weight: inherit !important;\"><\/div>\n<div id=\"crayon-54e4e27dbe658096522871-6\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">name\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 value\u00a0\u00a0\u00a0\u00a0 rate severity\u00a0\u00a0category\u00a0\u00a0aspect\u00a0\u00a0\u00a0\u00a0description<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-7\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-8\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">flow_rcv_dot1q_tag_err\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 726\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a04 drop\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0flow\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0parse\u00a0\u00a0\u00a0\u00a0 Packets dropped: 802.1q tag not configured<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-9\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">flow_no_interface\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0726\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a04 drop\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0flow\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0parse\u00a0\u00a0\u00a0\u00a0 Packets dropped: invalid interface<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-10\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">flow_ipv6_disabled\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 1\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 drop\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0flow\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0parse\u00a0\u00a0\u00a0\u00a0 Packets dropped: IPv6 disabled on interface<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-11\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">flow_tcp_non_syn_drop\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 50\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 drop\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0flow\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0session\u00a0\u00a0 Packets dropped: non-SYN TCP without session match<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-12\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">flow_fwd_l3_mcast_drop\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a050\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 drop\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0flow\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0forward\u00a0\u00a0 Packets dropped: no route for IP multicast<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-13\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">flow_fwd_l3_ttl_zero\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 9\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 drop\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0flow\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0forward\u00a0\u00a0 Packets dropped: IP TTL reaches zero<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-14\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">flow_fwd_zonechange\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a08\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 drop\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0flow\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0forward\u00a0\u00a0 Packets dropped: forwarded to different zone<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-15\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">flow_dos_pf_ipspoof\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 17\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 drop\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0flow\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0dos\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Packets dropped: Zone protection option &#8216;discard-ip-spoof&#8217;<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-16\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">flow_dos_pf_noreplyttl\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 6\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a00 drop\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0flow\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0dos\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Packets dropped: Zone protection option &#8216;suppress-icmp-timeexceeded&#8217;<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-17\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-18\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">Total counters shown: 9<\/div>\n<div id=\"crayon-54e4e27dbe658096522871-19\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">Examining the Session Table<\/h2>\n<p style=\"color: #141412;\">If a network connection failure is not found in the traffic log, the session table can be asked for sessions in DISCARD state, filtered based on its source, or whatever.\u00a0<strong>This is useful at the console because the session browser in the GUI does not store the filter options and is therefore a bit unhandy.<\/strong>\u00a0All commands start with \u201cshow session all filter \u2026\u201d, e.g.:<\/p>\n<div id=\"crayon-54e4e27dbe666517183887\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe666517183887-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe666517183887-2\">2<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe666517183887-3\">3<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe666517183887-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show session all filter state discard<\/div>\n<div id=\"crayon-54e4e27dbe666517183887-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">show session all filter application dns destination 8.8.8.8<\/div>\n<div id=\"crayon-54e4e27dbe666517183887-3\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show session all filter from trust to untrust application ssl state active<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">To see whether there are some \u201cpredict\u201d sessions in which the Palo Alto uses a ALG (appliation layer gateway) to\u00a0<strong>predict dynamic ports<\/strong>\u00a0(e.g., SIP, active FTP), use this command:<\/p>\n<div id=\"crayon-54e4e27dbe671310987865\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe671310987865-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe671310987865-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show session all filter type predict<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">A specific session can then be\u00a0<strong>cleared<\/strong>\u00a0with:<\/p>\n<div id=\"crayon-54e4e27dbe67b260963702\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe67b260963702-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe67b260963702-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">clear session id &lt;value&gt;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">Reason for Session Close<\/h2>\n<p style=\"color: #141412;\">You cannot see the reason for a closed session in the traffic log in the GUI. For this purpose, find out the session id in the traffic log and type in the following command in the CLI (Named the \u201c<a style=\"color: #bc360a;\" href=\"https:\/\/live.paloaltonetworks.com\/docs\/DOC-7240\" target=\"_blank\">Session Tracker<\/a>\u201c).\u00a0<strong>Note the last line in the output, e.g. \u201ctracker stage firewall : Aged out\u201d or \u201ctracker stage firewall : TCP FIN\u201d.<\/strong>\u00a0This shows what reason the firewall sees when it ends a session:<\/p>\n<div id=\"crayon-54e4e27dbe686059606413\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe686059606413-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe686059606413-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show session id &lt;id&gt;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">Alternatively, the\u00a0<strong>traffic log on the CLI can display the session tracker<\/strong>\u00a0when used with the option \u201cshow-tracker equal yes\u201d such as:<\/p>\n<div id=\"crayon-54e4e27dbe690191352610\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate crayon-wrapped\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim wrap\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe690191352610-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe690191352610-2\">2<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe690191352610-3\">3<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe690191352610-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show log traffic show-tracker equal yes<\/div>\n<div id=\"crayon-54e4e27dbe690191352610-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">show log traffic show-tracker equal yes direction equal backward<\/div>\n<div id=\"crayon-54e4e27dbe690191352610-3\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show log traffic show-tracker equal yes direction equal backward app equal ipv6-icmp from equal pa-ripe-atlas<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">VPN Issues<\/h2>\n<p style=\"color: #141412;\">(Palo Alto:\u00a0<a style=\"color: #bc360a;\" href=\"https:\/\/live.paloaltonetworks.com\/docs\/DOC-3671\" target=\"_blank\">How to Troubleshoot VPN Connectivity Issues<\/a>). Though you can find many reasons for not working site-to-site VPNs in the system log in the GUI, some CLI commands might be useful.\u00a0<strong>To reveal whether packets traverse through a VPN connection, use this:<\/strong>\u00a0(it shows the number of encap\/decap packets and bytes, i.e., the actual traffic flow)<\/p>\n<div id=\"crayon-54e4e27dbe69b051339128\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe69b051339128-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe69b051339128-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show vpn flow name &lt;value&gt;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">Or use the counter values for ipsec issues:<\/p>\n<div id=\"crayon-54e4e27dbe6a5362731946\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe6a5362731946-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe6a5362731946-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show counter global filter delta yes | match ipsec<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">And for a detailled debugging of IKE,\u00a0<strong>enable the debug<\/strong>\u00a0(without any more options)<\/p>\n<div id=\"crayon-54e4e27dbe6af866780662\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe6af866780662-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe6af866780662-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">debug ike pcap on<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">then\u00a0<strong>follow the pcap<\/strong>\u00a0with<\/p>\n<div id=\"crayon-54e4e27dbe6b9362035367\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe6b9362035367-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe6b9362035367-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">view-pcap follow yes debug-pcap ikemgr.pcap<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">and do NOT forget to\u00a0<strong>set the debugging off!<\/strong><\/p>\n<div id=\"crayon-54e4e27dbe6c3567901239\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe6c3567901239-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe6c3567901239-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">debug ike pcap off<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">The complete ikemgr.pcap can be\u00a0<strong>downloaded<\/strong>\u00a0from the Palo with scp or tftp, e.g.:<\/p>\n<div id=\"crayon-54e4e27dbe6cd820851331\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe6cd820851331-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe6cd820851331-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">scp export debug-pcap from ikemgr.pcap to &lt;username@host:path&gt;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">Displaying the Config in Set Mode<\/h2>\n<p style=\"color: #141412;\">The XML output of the \u201cshow config running\u201d command might be unpractical when troubleshooting at the console.\u00a0<strong>That\u2019s why the output format can be set to \u201cset\u201d mode:<\/strong><\/p>\n<div id=\"crayon-54e4e27dbe6d7987464914\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe6d7987464914-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe6d7987464914-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">set cli config-output-format set<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">Now, enter the\u00a0\u00a0<span id=\"crayon-54e4e27dbe6e1096433118\" class=\"crayon-syntax crayon-syntax-inline  crayon-theme-classic crayon-theme-classic-inline crayon-font-monaco\"><span class=\"crayon-pre crayon-code\" style=\"color: #000000;\">configure<\/span><\/span>\u00a0 mode and type\u00a0<span id=\"crayon-54e4e27dbe6eb168851058\" class=\"crayon-syntax crayon-syntax-inline  crayon-theme-classic crayon-theme-classic-inline crayon-font-monaco\"><span class=\"crayon-pre crayon-code\" style=\"color: #000000;\">show<\/span><\/span>\u00a0. This reveals the complete configuration with \u201cset \u2026\u201d commands. Here is a sample output of a particular show command:<\/p>\n<div id=\"crayon-54e4e27dbe6f5863793432\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num crayon-marked-num crayon-top crayon-bottom\" style=\"font-weight: inherit !important; color: #1561ac !important;\" data-line=\"crayon-54e4e27dbe6f5863793432-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe6f5863793432-2\">2<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe6f5863793432-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe6f5863793432-4\">4<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe6f5863793432-5\">5<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe6f5863793432-6\">6<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe6f5863793432-7\">7<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe6f5863793432-1\" class=\"crayon-line crayon-marked-line crayon-top crayon-bottom\" style=\"font-weight: inherit !important;\">weberjoh@fd-wv-fw02# show network interface ethernet ethernet1\/1<\/div>\n<div id=\"crayon-54e4e27dbe6f5863793432-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">set network interface ethernet ethernet1\/1 layer3 ip 172.16.1.2\/24<\/div>\n<div id=\"crayon-54e4e27dbe6f5863793432-3\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">set network interface ethernet ethernet1\/1 layer3 untagged-sub-interface no<\/div>\n<div id=\"crayon-54e4e27dbe6f5863793432-4\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">set network interface ethernet ethernet1\/1 layer3 interface-management-profile ping<\/div>\n<div id=\"crayon-54e4e27dbe6f5863793432-5\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">set network interface ethernet ethernet1\/1 link-speed auto<\/div>\n<div id=\"crayon-54e4e27dbe6f5863793432-6\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">set network interface ethernet ethernet1\/1 link-duplex auto<\/div>\n<div id=\"crayon-54e4e27dbe6f5863793432-7\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">set network interface ethernet ethernet1\/1 link-state auto<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">The\u00a0<strong>pipe<\/strong>\u00a0(|) can be used to grep certain values with the \u201c<strong>match<\/strong>\u201d keyword, such as:<\/p>\n<div id=\"crayon-54e4e27dbe6ff487632068\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe6ff487632068-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe6ff487632068-2\">2<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe6ff487632068-3\">3<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe6ff487632068-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">weberjoh@fd-wv-fw02# show | match 192.168.120.2<\/div>\n<div id=\"crayon-54e4e27dbe6ff487632068-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">set deviceconfig system ip-address 192.168.120.2<\/div>\n<div id=\"crayon-54e4e27dbe6ff487632068-3\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">set address h_fd-wv-fw02_mgmt ip-netmask 192.168.120.2<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">To show the complete config\u00a0<strong>without breaks<\/strong>\u00a0(which is \u201cterminal length 0\u2033 on Cisco devices), the following command can be used:<\/p>\n<div id=\"crayon-54e4e27dbe70a310182458\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe70a310182458-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe70a310182458-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">set cli pager off<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">Export\/Import Files<\/h2>\n<p style=\"color: #141412;\"><strong>To copy files from or to the Palo Alto firewall,<\/strong>\u00a0scp or tftp can be used. The commands have both the same structure with \u201cexport \u2026 to\u201d or \u201cimport \u2026 from\u201d, e.g.:<\/p>\n<div id=\"crayon-54e4e27dbe714270973399\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe714270973399-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe714270973399-2\">2<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe714270973399-3\">3<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe714270973399-4\">4<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe714270973399-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">scp export log system to &lt;username@host:path_to_destination_filename&gt;<\/div>\n<div id=\"crayon-54e4e27dbe714270973399-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">scp import software from &lt;username@host:path&gt;<\/div>\n<div id=\"crayon-54e4e27dbe714270973399-3\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">tftp export configuration from running-config.xml to &lt;tftp-host&gt;<\/div>\n<div id=\"crayon-54e4e27dbe714270973399-4\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">tftp import url-block-page from &lt;tftp-host&gt;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">User-IDs and Groups<\/h2>\n<p style=\"color: #141412;\">State of the\u00a0<strong>LDAP server connections:<\/strong><\/p>\n<div id=\"crayon-54e4e27dbe71e656981680\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe71e656981680-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe71e656981680-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show user group-mapping state all<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">List the\u00a0<strong>groups<\/strong>\u00a0that are stored in the Palo Alto:<\/p>\n<div id=\"crayon-54e4e27dbe728187235620\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe728187235620-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe728187235620-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show user group list<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">Manual group mapping\u00a0<strong>refresh<\/strong>:<\/p>\n<div id=\"crayon-54e4e27dbe732647982851\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe732647982851-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe732647982851-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">debug user-id refresh group-mapping all<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\"><strong>Show the group memberships for a particular user:<\/strong><\/p>\n<div id=\"crayon-54e4e27dbe73c366696479\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe73c366696479-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe73c366696479-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show user user-IDs match-user &lt;value&gt;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\"><strong>IP to User mapping:<\/strong><\/p>\n<div id=\"crayon-54e4e27dbe745940359927\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe745940359927-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe745940359927-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show user ip-user-mapping all<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">User-ID cache clearance:<\/p>\n<div id=\"crayon-54e4e27dbe74f628102989\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe74f628102989-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe74f628102989-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">clear user-cache all<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">IP Addresses of FQDN Objects<\/h2>\n<p style=\"color: #141412;\">When using objects with FQDNs, the current IP addresses are not shown in the GUI. The following command displays respectively refreshes them:<\/p>\n<div id=\"crayon-54e4e27dbe759139650947\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe759139650947-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe759139650947-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">request system fqdn { show | refresh }<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">IP Addresses of Dynamic Block Lists<\/h2>\n<p style=\"color: #141412;\">Similar, the entries in a dynamic block list can be viewed with:<\/p>\n<div id=\"crayon-54e4e27dbe763655778467\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe763655778467-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe763655778467-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">request system external-list show name &lt;name-of-the-list&gt;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">DNS Proxy<\/h2>\n<p style=\"color: #141412;\">To verify the functionality of DNS proxy objects, at least two commands are useful. Both outputs should speak for themselves:<\/p>\n<div id=\"crayon-54e4e27dbe76d615733617\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe76d615733617-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe76d615733617-2\">2<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe76d615733617-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show dns-proxy statistics all<\/div>\n<div id=\"crayon-54e4e27dbe76d615733617-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">show dns-proxy cache all<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h2 style=\"color: #141412;\">Active URL Vendor\/Database<\/h2>\n<p style=\"color: #141412;\">I had some issues with the two different URL databases \u201cbrightcloud\u201d and \u201cPAN-DB\u201d. This is the command to show unambiguously which vendor is active on the PA (independent of the licenses):<\/p>\n<div id=\"crayon-54e4e27dbe777150863975\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe777150863975-1\">1<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe777150863975-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show system setting url-database<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">The output is either \u201cbrightcloud\u201d or \u201cpaloaltonetworks\u201d. The standard URL DB up to PAN-OS 5.0 is brightcloud. Beginning with PAN-OS 6.0, the default is PAN-DB (refer to the release notes, section \u201cChanges to Default Behavior\u201d). To change the vendor (of course only if it is licensed), click the \u201cActivate\u201d link under licenses in the GUI.<\/p>\n<h2 style=\"color: #141412;\">PAN-DB URL Test &amp; Cache<\/h2>\n<p style=\"color: #141412;\">To show the category of a specific URL, use one of the following commands:<\/p>\n<div id=\"crayon-54e4e27dbe782665216803\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe782665216803-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe782665216803-2\">2<\/div>\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe782665216803-3\">3<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe782665216803-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">test url &lt;fqdn&gt;<\/div>\n<div id=\"crayon-54e4e27dbe782665216803-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">test url-info-cloud &lt;fqdn&gt;<\/div>\n<div id=\"crayon-54e4e27dbe782665216803-3\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">test url-info-host &lt;fqdn&gt;<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p style=\"color: #141412;\">To display the current URL cache from the PAN-DB, two steps are required. The first one is the creation of a logfile which contains all entries and the second one is to display this logfile:<\/p>\n<div id=\"crayon-54e4e27dbe78c062317152\" class=\"crayon-syntax crayon-theme-classic crayon-font-monaco crayon-os-pc print-yes notranslate\" style=\"color: #141412;\" data-settings=\" no-popup minimize scroll-always disable-anim\">\n<div class=\"crayon-plain-wrap\"><\/div>\n<div class=\"crayon-main\">\n<table class=\"crayon-table\">\n<tbody>\n<tr class=\"crayon-row\">\n<td class=\"crayon-nums \" style=\"color: #5499de !important;\" data-settings=\"show\">\n<div class=\"crayon-nums-content\">\n<div class=\"crayon-num\" style=\"font-weight: inherit !important;\" data-line=\"crayon-54e4e27dbe78c062317152-1\">1<\/div>\n<div class=\"crayon-num crayon-striped-num\" style=\"font-weight: inherit !important; color: #317cc5 !important;\" data-line=\"crayon-54e4e27dbe78c062317152-2\">2<\/div>\n<\/div>\n<\/td>\n<td class=\"crayon-code\">\n<div class=\"crayon-pre\">\n<div id=\"crayon-54e4e27dbe78c062317152-1\" class=\"crayon-line\" style=\"font-weight: inherit !important;\">show system setting url-cache all<\/div>\n<div id=\"crayon-54e4e27dbe78c062317152-2\" class=\"crayon-line crayon-striped-line\" style=\"font-weight: inherit !important;\">less dp-log dp_url_DB.log<\/div>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>Stolen from:\u00a0http:\/\/blog.webernetz.net\/2013\/11\/21\/cli-commands-for-troubleshooting-palo-alto-firewalls\/ \u00a0&lt;&#8212; I took this just in case it ever went offline and I still use this for reference. \ud83d\ude42 \u00a0contact me if I&#8217;m in violation! lol<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>When troubleshooting network and security issues on many different devices I always miss some command options to do exactly what I want to do on the device I am currently working with. Therefore,\u00a0I list a few commands for the Palo Alto Networks firewalls to have a short reference for myself.\u00a0Maybe some other network professionals will [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-585","post","type-post","status-publish","format-standard","hentry","category-geek","post-preview"],"_links":{"self":[{"href":"https:\/\/www.echorequest.com\/index.php?rest_route=\/wp\/v2\/posts\/585","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.echorequest.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.echorequest.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.echorequest.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.echorequest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=585"}],"version-history":[{"count":2,"href":"https:\/\/www.echorequest.com\/index.php?rest_route=\/wp\/v2\/posts\/585\/revisions"}],"predecessor-version":[{"id":587,"href":"https:\/\/www.echorequest.com\/index.php?rest_route=\/wp\/v2\/posts\/585\/revisions\/587"}],"wp:attachment":[{"href":"https:\/\/www.echorequest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=585"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.echorequest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=585"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.echorequest.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}