<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FIPS-CC cannot log into firewall in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fips-cc-cannot-log-into-firewall/m-p/1228224#M5868</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206204"&gt;@sos66sos&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It does indeed sound like you're running into a memory leak issue where a certain process takes hold of all the resources over time and rendering the device unresponsive.&lt;/P&gt;
&lt;P&gt;If you generate a tech support file you should be able to check the resources over time and especially at the time you're experiencing the issue.&amp;nbsp; Check for a process that hogs all the resources.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A workaround would be to restart said process, there should be a cli command to restart the appropriate process.&lt;/P&gt;
&lt;P&gt;11.1.6-h3 is currently the preferred release in this OS train. So you might want to submit the TSF to support for analysis.&lt;/P&gt;
&lt;P&gt;Submitting your TSF will confirm if you're hitting a known bug or if you're hitting a different issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
    <pubDate>Tue, 06 May 2025 07:42:15 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2025-05-06T07:42:15Z</dc:date>
    <item>
      <title>FIPS-CC cannot log into firewall</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fips-cc-cannot-log-into-firewall/m-p/1227777#M5856</link>
      <description>&lt;P&gt;We have an HA pair PA-440's running 11.1.6-h3 in FIPS-CC&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Recently the Active firewall stopped allowing us to log into it or connect with Global Protect using local user accounts.&amp;nbsp; Neiither the GUI or SSH works - it just times out.&amp;nbsp; Seeing how its in FIPS-CC mode the console port is turned off so I could not test access via console.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The standby firewall allows you to log into it just fine.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I pulled the primary firewall and turned it off for a day or 2.&amp;nbsp; When I turned it back on, you could log into it but that only lasted a few days and the issue returned.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;One item I noticed is the Management plane had a very high CPU - normally between 60-80%.&amp;nbsp; I'm not sure if there is a runaway process that eventually kills the Management plane?&lt;BR /&gt;&lt;BR /&gt;Has anyone had this issue?&amp;nbsp; If so what did you do to remediate it - maybe turn something off or an OS version?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 16:00:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fips-cc-cannot-log-into-firewall/m-p/1227777#M5856</guid>
      <dc:creator>sos66sos</dc:creator>
      <dc:date>2025-04-30T16:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS-CC cannot log into firewall</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fips-cc-cannot-log-into-firewall/m-p/1227853#M5857</link>
      <description>&lt;P&gt;Your PA-440 firewall running PAN-OS 11.1.6-h3 in FIPS-CC mode is experiencing high CPU usage on the management plane, leading to login issues. Some users have reported similar problems, and rolling back to PAN-OS 11.1.4-h1 helped stabilize performance.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206204"&gt;@sos66sos&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;We have an HA pair PA-440's running 11.1.6-h3 in FIPS-CC&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Recently the Active firewall stopped allowing us to log into it or connect with Global Protect using local user accounts.&amp;nbsp; Neiither the GUI or SSH works - it just times out.&amp;nbsp; Seeing how its in FIPS-CC mode the console port is turned off so I could not test access via console.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The standby firewall allows you to log into it just fine.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I pulled the primary firewall and turned it off for a day or 2.&amp;nbsp; When I turned it back on, you could log into it but that only lasted a few days and the issue returned.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;One item I noticed is the Management plane had a very high CPU - normally between 60-80%.&amp;nbsp; I'm not sure if there is a runaway process that eventually kills the Management plane?&lt;BR /&gt;&lt;BR /&gt;Has anyone had this issue?&amp;nbsp; If so what did you do to remediate it - maybe turn something off or an OS version?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 May 2025 10:04:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fips-cc-cannot-log-into-firewall/m-p/1227853#M5857</guid>
      <dc:creator>coniveh699</dc:creator>
      <dc:date>2025-05-01T10:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS-CC cannot log into firewall</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/fips-cc-cannot-log-into-firewall/m-p/1228224#M5868</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206204"&gt;@sos66sos&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It does indeed sound like you're running into a memory leak issue where a certain process takes hold of all the resources over time and rendering the device unresponsive.&lt;/P&gt;
&lt;P&gt;If you generate a tech support file you should be able to check the resources over time and especially at the time you're experiencing the issue.&amp;nbsp; Check for a process that hogs all the resources.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A workaround would be to restart said process, there should be a cli command to restart the appropriate process.&lt;/P&gt;
&lt;P&gt;11.1.6-h3 is currently the preferred release in this OS train. So you might want to submit the TSF to support for analysis.&lt;/P&gt;
&lt;P&gt;Submitting your TSF will confirm if you're hitting a known bug or if you're hitting a different issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Tue, 06 May 2025 07:42:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/fips-cc-cannot-log-into-firewall/m-p/1228224#M5868</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-05-06T07:42:15Z</dc:date>
    </item>
  </channel>
</rss>

