<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewallcrash because of Application cloud Engine (ACE) in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewallcrash-because-of-application-cloud-engine-ace/m-p/595825#M3630</link>
    <description>&lt;P&gt;Hi community&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since about 2 weeks a vm firewall started getting problems with random crashes. Our setup is a firewallcluster but so far the active firewall crashes almost completely silent. At least the firewall does not initiate a failover to the passive node. So far we had about 4 crashes at random times and in one case the firewall crashed "hard" enough that it rebooted and this way the passive firewall took over.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TAC is already analyzing the situation. So far it is still very unclear (and frustrating). It seems to be related to the application cloud engine. This is also the current recommendation / action plan: we should disable the ACE completely for the moment. Obviously we did not buy this subscription for fun - we actively use these additional App-IDs from the SaaS Inline subscription. Disabling this of course will lead to the next issues. These issues will may be no longer be crashes but the traffic control obviously will be restricted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At this point on one side I wanted to warn you as there seems to be a critical issue in PAN-OS in combination with SaaS Inline and application cloud engine (ACE). As we were told, this issue was introduced in code starting with PAN-OS 10.1. On the other side I wanted to ask if you had similar or the same issue already and if you maybe found a solution/workaround for this already (which was not disabling the feature completely)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great weekend&lt;/P&gt;
&lt;P&gt;Remo&lt;/P&gt;</description>
    <pubDate>Sat, 24 Aug 2024 12:27:17 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2024-08-24T12:27:17Z</dc:date>
    <item>
      <title>Firewallcrash because of Application cloud Engine (ACE)</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewallcrash-because-of-application-cloud-engine-ace/m-p/595825#M3630</link>
      <description>&lt;P&gt;Hi community&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since about 2 weeks a vm firewall started getting problems with random crashes. Our setup is a firewallcluster but so far the active firewall crashes almost completely silent. At least the firewall does not initiate a failover to the passive node. So far we had about 4 crashes at random times and in one case the firewall crashed "hard" enough that it rebooted and this way the passive firewall took over.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TAC is already analyzing the situation. So far it is still very unclear (and frustrating). It seems to be related to the application cloud engine. This is also the current recommendation / action plan: we should disable the ACE completely for the moment. Obviously we did not buy this subscription for fun - we actively use these additional App-IDs from the SaaS Inline subscription. Disabling this of course will lead to the next issues. These issues will may be no longer be crashes but the traffic control obviously will be restricted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At this point on one side I wanted to warn you as there seems to be a critical issue in PAN-OS in combination with SaaS Inline and application cloud engine (ACE). As we were told, this issue was introduced in code starting with PAN-OS 10.1. On the other side I wanted to ask if you had similar or the same issue already and if you maybe found a solution/workaround for this already (which was not disabling the feature completely)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great weekend&lt;/P&gt;
&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Sat, 24 Aug 2024 12:27:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/firewallcrash-because-of-application-cloud-engine-ace/m-p/595825#M3630</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2024-08-24T12:27:17Z</dc:date>
    </item>
  </channel>
</rss>

