<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not updating low traffic session status with hw offload enabled in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/not-updating-low-traffic-session-status-with-hw-offload-enabled/m-p/538728#M1138</link>
    <description>&lt;P&gt;For future generations - issue&amp;nbsp;PAN-216314.&amp;nbsp;&lt;SPAN&gt;Long story short - there are two ways DP is registering offloaded traffic counters - traffic and time based (&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm8cCAC" target="_self"&gt;Disable Firewall offloading traffic&lt;/A&gt;) and time based mechanism was disabled after the upgrade.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;When running "&lt;EM&gt;debug dataplane internal pdt fe100 csr rd name sem_ctrl&lt;/EM&gt;" in case of this issue value was&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;EM&gt; [&amp;nbsp;&amp;nbsp;&amp;nbsp; 8] ctr_scan_dis&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; =&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 (0x1)&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;... but it should be 0.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can be changed via "&lt;EM&gt;debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value 0&lt;/EM&gt;".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;There is no interruption in traffic, has to be done on each HA node.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Use at your own risk.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Apr 2023 07:17:20 GMT</pubDate>
    <dc:creator>nikoo</dc:creator>
    <dc:date>2023-04-14T07:17:20Z</dc:date>
    <item>
      <title>Not updating low traffic session status with hw offload enabled</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/not-updating-low-traffic-session-status-with-hw-offload-enabled/m-p/534325#M1016</link>
      <description>&lt;P&gt;PA-32xx series with 10.1.9 (issue showed up after upgrade)&lt;/P&gt;
&lt;P&gt;There is long-lasting SSH session where only something like keepalive is sent every 5 minutes or so. With hardware offload enabled, this traffic is not registered in the dataplane (session stats are not increasing even though there is traffic for that session) and subsequently TTL is not reset and session breaks after hour (TCP timeout).&lt;/P&gt;
&lt;P&gt;If HW offload is disabled - everything works as expected, each keepalive resets TCP session TTL.&lt;/P&gt;
&lt;P&gt;it looks like the same behavior was seen on other "low traffic" sessions, but SSH is the most obvious one.&lt;/P&gt;
&lt;P&gt;Currently there is TAC case open and under research, but I have a feeling this may be wider issue, so maybe there's already feedback on this?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 08:13:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/not-updating-low-traffic-session-status-with-hw-offload-enabled/m-p/534325#M1016</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2023-03-14T08:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Not updating low traffic session status with hw offload enabled</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/not-updating-low-traffic-session-status-with-hw-offload-enabled/m-p/535517#M1074</link>
      <description>&lt;P&gt;You may not&amp;nbsp; see it as it is offloaded but have you checked if you create a new service just to change the timeout for example to 4/3 minutes what happens?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMbvCAG" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMbvCAG&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also test application overide:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVLCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVLCA0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 07:16:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/not-updating-low-traffic-session-status-with-hw-offload-enabled/m-p/535517#M1074</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2023-03-23T07:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Not updating low traffic session status with hw offload enabled</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/not-updating-low-traffic-session-status-with-hw-offload-enabled/m-p/538728#M1138</link>
      <description>&lt;P&gt;For future generations - issue&amp;nbsp;PAN-216314.&amp;nbsp;&lt;SPAN&gt;Long story short - there are two ways DP is registering offloaded traffic counters - traffic and time based (&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm8cCAC" target="_self"&gt;Disable Firewall offloading traffic&lt;/A&gt;) and time based mechanism was disabled after the upgrade.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;When running "&lt;EM&gt;debug dataplane internal pdt fe100 csr rd name sem_ctrl&lt;/EM&gt;" in case of this issue value was&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;EM&gt; [&amp;nbsp;&amp;nbsp;&amp;nbsp; 8] ctr_scan_dis&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; =&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 (0x1)&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;... but it should be 0.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can be changed via "&lt;EM&gt;debug dataplane internal pdt fe100 csr wr_sem_ctrl_ctr_scan_dis value 0&lt;/EM&gt;".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;There is no interruption in traffic, has to be done on each HA node.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Use at your own risk.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 07:17:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/not-updating-low-traffic-session-status-with-hw-offload-enabled/m-p/538728#M1138</guid>
      <dc:creator>nikoo</dc:creator>
      <dc:date>2023-04-14T07:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: Not updating low traffic session status with hw offload enabled</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/not-updating-low-traffic-session-status-with-hw-offload-enabled/m-p/544486#M1373</link>
      <description>&lt;P&gt;Hello, did the TAC give you any solution?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 03:29:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/not-updating-low-traffic-session-status-with-hw-offload-enabled/m-p/544486#M1373</guid>
      <dc:creator>NicolasReyes</dc:creator>
      <dc:date>2023-06-02T03:29:16Z</dc:date>
    </item>
  </channel>
</rss>

