For EX3400 switches in Mist.
In the scenario presented, the customer always had EX3400 and recently purchased EX4000 switches, and on the EX4000 when the pcap is ran on a trunk port, the customer is able to see TCP transit traffic, and the customer had the doubt as of why this was not the same on EX3400s
How it works on EX4400: Transit path packets are captured via JTI sensors (the /junos/system/linecard/packet-capture/ sensor), in addition to the standard tcpdump for CPU-bound traffic. The Mist agent translates your filter expression into a Junos Firewall Filter and writes it to the mist-pcap ephemeral config DB. Both streams are merged transparently before being published to the Mist cloud.
Models that support transit traffic (CPU + transit):
Models that do NOT support transit traffic (CPU/unicast only):