How to collect wireshark on multiple interface when global protect client is connected

How to collect wireshark on multiple interface when global protect client is connected

130
Created On 07/08/26 02:11 AM - Last Modified 07/08/26 20:40 PM


Objective


When troubleshooting GlobalProtect connectivity or traffic issues, it is often necessary to capture packets on both your physical network interface (Wi-Fi/Ethernet) and the GlobalProtect virtual adapter simultaneously. This allows you to see both the encrypted tunnel traffic and the unencrypted traffic passing through the VPN



Environment


Global Protect

Wireshark Installed



Procedure


STEP 1..Identify your active physical connection (e.g., Wi-Fi or Ethernet).

Identify the GlobalProtect virtual interface (typically labeled PANGP Virtual Ethernet Adapter on Windows, or gpn0 / gpn1 on macOS).

Finding the Adapter on Windows

  1. Press the Windows Key + R to open the Run dialog box
  2. Type ncpa.cpl and press Enter to open Network Connections.
  3. Look for the adapter labeled GlobalProtect or the one listing Palo Alto Networks (PANGP Virtual Ethernet Adapter) in its description.

 

Finding the Adapter on MAC

  1. Open GlobalProtect Settings > Connection and note your Assigned IP Address.
  2. Open Terminal and run the following command (replace YOUR_VPN_IP with your actual IP) to reveal your interface name (e.g., gpn0 or utun2):
  3. ifconfig | grep -B 2 "YOUR_VPN_IP"
  4. The top line of the output will display the exact interface name (e.g., gpn0 or utun) to select in Wireshark.

STEP  2.Launch Wireshark: Open Wireshark on the client machine.

STEP  3.Locate the Interfaces: On the Wireshark home screen, you will see a list of available network interfaces under the Capture section.

Hold down the Ctrl key (Windows) or Command (⌘) key (macOS) and click on each of these interfaces to highlight both.

*Windows*

MAC Machine

(Optional: You can use the Shift key if you need to select a continuous block of consecutive interfaces)

STEP 4.Start the Capture: Once both interfaces are highlighted, click the blue shark fin icon in the top-left corner of the toolbar to begin recording traffic.

STEP 5.Reproduce the Issue: Perform the actions that demonstrate the network issue you are investigating.

STEP 6.Stop and Save: * Click the red square icon in the top toolbar to stop the capture and save as .pcapng

STEP 7.Collect GP client logs : https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kI6UCAU



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000wlaHKAQ&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail