Where Can I Use This? | What Do I Need? |
The On-demand Packet Capture (PCAP) feature for next-generation firewalls
allows you to authorize the IoT Security Research Team to perform packet
captures and automatically upload the captured packet files to IoT Security for
offline analysis. The IoT Security Research Team takes packet captures only when
necessary, such as when an unknown device or an unknown application appears on your
network and the information required to assess the situation can be obtained no
other way. The scope of such packet captures is limited so that they don’t affect
normal firewall operations.
PCAP files are securely stored and only accessed by IoT Security Research
Team members. The files will be deleted either manually after an analysis is
complete or automatically after 30 days elapse.
For the IoT Security Research Team to use PCAP to collect network traffic
metadata from a firewall, you must first authorize the firewall to allow packet
capturing.
To support PCAP on firewalls, they must be running:
- PAN-OS 10.2.10 or later 10.2 releases
- PAN-OS 11.0.4 or later 11.0 releases
- PAN-OS 11.1.0 or later