<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: flow_fpga_ingress_exception_err and high latency in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460720#M102101</link>
    <description>&lt;P&gt;There is no asymmetric routing, but we did look into that as well. We did do a packet filter and look at the drops for a single session that was experiencing latency. There were no drops. Its just slow! Very frustrating..&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for the suggestion!&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jan 2022 20:52:31 GMT</pubDate>
    <dc:creator>Alex_Huthmacher</dc:creator>
    <dc:date>2022-01-24T20:52:31Z</dc:date>
    <item>
      <title>flow_fpga_ingress_exception_err and high latency</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460305#M102059</link>
      <description>&lt;P&gt;Recently deployed several PA-5250s Running 10.1.3 and there is a issue that randomly comes and goes.&lt;BR /&gt;&lt;BR /&gt;Latency for traffic going through the firewalls spikes to 100-500ms. I was able to capture one thing that looked peculiar and that was&amp;nbsp;flow_fpga_ingress_exception_err counts were high (8169388322) and the rate was high (12468). But I can't seem to find a good definition as what this would indicate.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I also caught the packet descriptor (on-chip) (average):&amp;nbsp; with 100 across the first two rows.&amp;nbsp;&lt;BR /&gt;I failed to capture the CPU Cores at the same time though.&amp;nbsp;&lt;BR /&gt;Any ideas?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 21:00:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460305#M102059</guid>
      <dc:creator>Alex_Huthmacher</dc:creator>
      <dc:date>2022-01-21T21:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: flow_fpga_ingress_exception_err and high latency</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460313#M102062</link>
      <description>&lt;P&gt;Known issue:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-release-notes/pan-os-10-1-3-known-and-addressed-issues/pan-os-10-1-3-known-issues.html" target="_self"&gt;PAN-141630&lt;/A&gt; seems to match this scenario. Interestingly, 10.1.3 is the &lt;A href="https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-p/258304" target="_self"&gt;preferred&lt;/A&gt; 10.1 version as of today. Therefore, upgrade to 10.1.4 may not be the best solution (yet).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may be able to get more context looking at global counters: &lt;EM&gt;show counter global | match fpga&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 21:41:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460313#M102062</guid>
      <dc:creator>Gustavo_Aristi</dc:creator>
      <dc:date>2022-01-21T21:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: flow_fpga_ingress_exception_err and high latency</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460422#M102071</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/145185"&gt;@Alex_Huthmacher&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If this is mission critical hardware, and you don't&amp;nbsp;&lt;STRONG&gt;require&amp;nbsp;&lt;/STRONG&gt;features in 10.1, I would&amp;nbsp;&lt;EM&gt;highly&amp;nbsp;&lt;/EM&gt;recommend staying off of 10.1 for the time being. There's still bugs getting worked out in 10.1 and 10.0 is a fairly stable release at this point.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jan 2022 05:08:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460422#M102071</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-01-23T05:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: flow_fpga_ingress_exception_err and high latency</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460649#M102093</link>
      <description>&lt;P&gt;Thanks for the help, I asked TAC if we should downgrade and they replied with "why?".&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 16:59:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460649#M102093</guid>
      <dc:creator>Alex_Huthmacher</dc:creator>
      <dc:date>2022-01-24T16:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: flow_fpga_ingress_exception_err and high latency</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460695#M102095</link>
      <description>&lt;P&gt;I would ask the same question as you currently are running the preferred/stable version of 10.1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, instead of questioning you, I hope they are providing a solution as you seem to already have a case with them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am curious to hear what their solution was, if they provide one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 19:37:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460695#M102095</guid>
      <dc:creator>Gustavo_Aristi</dc:creator>
      <dc:date>2022-01-24T19:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: flow_fpga_ingress_exception_err and high latency</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460717#M102098</link>
      <description>&lt;P&gt;Well right now they have told us that high&lt;SPAN&gt;&amp;nbsp;flow_fpga_ingress_exception_err are expected behavior and not to worry about them. As for the latency, we are just shot-gunning a few changes to see if anything helps. Like reducing port channel&amp;nbsp;down to one link, possibly disabling offloading, and a couple others. Last resort is downgrade&amp;nbsp;to the preferred&amp;nbsp;9 code. I will let you know if I find anything.&amp;nbsp;&lt;BR /&gt;The reason we suggest the downgrade is because we have one 5220 running 9 code and it doesn't experience this issue. That's all we got though.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 20:35:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460717#M102098</guid>
      <dc:creator>Alex_Huthmacher</dc:creator>
      <dc:date>2022-01-24T20:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: flow_fpga_ingress_exception_err and high latency</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460719#M102100</link>
      <description>&lt;P&gt;Any idea if there's any asymmetric routing going on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Packet capture combined with global counters may shed some light on this. If you manage to narrow this down, to a &lt;STRONG&gt;sample&lt;/STRONG&gt; source and destination that would be perfect. Then see if you get a drop pcap and use the pcap filters against the global counters.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 20:43:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460719#M102100</guid>
      <dc:creator>Gustavo_Aristi</dc:creator>
      <dc:date>2022-01-24T20:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: flow_fpga_ingress_exception_err and high latency</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460720#M102101</link>
      <description>&lt;P&gt;There is no asymmetric routing, but we did look into that as well. We did do a packet filter and look at the drops for a single session that was experiencing latency. There were no drops. Its just slow! Very frustrating..&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for the suggestion!&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 20:52:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460720#M102101</guid>
      <dc:creator>Alex_Huthmacher</dc:creator>
      <dc:date>2022-01-24T20:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: flow_fpga_ingress_exception_err and high latency</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460735#M102103</link>
      <description>&lt;P&gt;I am sorry you are going through this, I am sure you'll find the solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point, since you are already at the pcap stage, I would perform a packet diagnostics, flow basic and look at a low level what the firewall is doing with each packet/session in the flow logic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I bet you are familiar with that or already tried it, but if not, below is a good read:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/debugging-packet-flow/td-p/67514" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/debugging-packet-flow/td-p/67514&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My approach for reading these is different, I get a TSF and find the txt file there and open it in notepad++&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 22:00:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/460735#M102103</guid>
      <dc:creator>Gustavo_Aristi</dc:creator>
      <dc:date>2022-01-24T22:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: flow_fpga_ingress_exception_err and high latency</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/465855#M102622</link>
      <description>&lt;P&gt;Hey Guys!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're having a very similar issue on our 5220 (PAN-OS 10.1.4). The latency comes and goes. CPU / Memory usage is close to nothing, same goes for session utilization. However every few secs the&amp;nbsp;flow_fpga_ingress_exception_err counter is rising. Delta says 50 more drops in a second, the next second 3000.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's a strange thing I noticed. We gather metrics with prometheus (nevermind the software), and monitoring IfHCOutOctets and&amp;nbsp;IfHCinOctets via snmp. We both monitor the firewall interfaces, and the (Cisco) switch ports they're connected to. We're using the same formula for bandwith calculation and get massive differences. On the switchport we see the nightly backups consume the whole 1Gbit bandwith on our graphs, in the same time period the matching firewall interface shows only ~700 Mbit/sec. It's the two ends of the same wire!&lt;/P&gt;&lt;P&gt;I'm not saying it's related to&amp;nbsp;flow_fpga_ingress_exception_err but packet drops (a few thousand per few secs) could explain the difference between the two measured values.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 14:04:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/465855#M102622</guid>
      <dc:creator>PozsonyiAttila</dc:creator>
      <dc:date>2022-02-15T14:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: flow_fpga_ingress_exception_err and high latency</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/465865#M102624</link>
      <description>&lt;P&gt;So just a quick update. The issue seamed to be related to the number of sessions we were getting through the firewall. We handle a large number of sessions of a particular protocol requests and it is our number one application by session each day. When we put an App-ID Override on the protocol it appears to have cleared up the latency.&amp;nbsp;&lt;BR /&gt;I am now skeptical of Palos session per second capability but if you look at the datasheets they always show the max session/s count using 1 byte http traffic with app-id override. So it is what it is. Good luck out there.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 14:43:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/465865#M102624</guid>
      <dc:creator>Alex_Huthmacher</dc:creator>
      <dc:date>2022-02-15T14:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: flow_fpga_ingress_exception_err and high latency</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/466163#M102658</link>
      <description>&lt;P&gt;Thanks for the update, I keep that in mind. My issue turned out to be ISP related so PAN-OS isn't guilty! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What a strange coincidence that was! Very, very similar issue and we came to the same (wrong) conclusion...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attila&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 12:02:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/flow-fpga-ingress-exception-err-and-high-latency/m-p/466163#M102658</guid>
      <dc:creator>PozsonyiAttila</dc:creator>
      <dc:date>2022-02-16T12:02:06Z</dc:date>
    </item>
  </channel>
</rss>

