<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Networking or Dataplane apparent reload (5200 w/10.1) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/networking-or-dataplane-apparent-reload-5200-w-10-1/m-p/524094#M108471</link>
    <description>&lt;P&gt;Hi and thank you for your reply. Upgrade to 10.1.8 is scheduled for this evening. I think you nailed the issue (i.e. who killed our OSPF):&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;2022-11-30 21:52:23.920 +0100 --- panio&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:Resource monitoring sampling data (per second):&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:CPU load sampling by group:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_lookup : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_fastpath : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_slowpath : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_forwarding : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_mgmt : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_ctrl : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:nac_result : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_np : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:dfa_result : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:module_internal : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:aho_result : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:zip_result : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:pktlog_forwarding : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:lwm : 0%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_host : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:fpga_result : 0%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:CPU load (%) during last 15 seconds: &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:core 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:core 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:core 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:Resource utilization (%) during last 15 seconds: &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:session:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:packet buffer:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The previous sampling (10 minutes before), which I won't post, sees all CPU core loads under 7%, and all zeros on packet buffers, which is consistent with the expected load for that timeframe (i.e. very low).&lt;BR /&gt;Any clue on how to further investigate the issue?&lt;/P&gt;</description>
    <pubDate>Wed, 14 Dec 2022 14:55:02 GMT</pubDate>
    <dc:creator>michelealbrigo</dc:creator>
    <dc:date>2022-12-14T14:55:02Z</dc:date>
    <item>
      <title>Networking or Dataplane apparent reload (5200 w/10.1)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/networking-or-dataplane-apparent-reload-5200-w-10-1/m-p/523977#M108455</link>
      <description>&lt;P&gt;I'm experiencing issues of what seems to be a "sudden restart" of all OSPF/OSPFv3 neighborship on a PA-5220/PanOS 10.1.6 firewall. I'm trying to pinpoint the root problem on my own, since our support contact (a partner, not PA's support) is taking the route that the problem is on OSPF neighbors' side, which is unlikely to be true, since it would mean that one device (PA) is working properly while 12 devices are having simultaneous problems of the exact same type on just the links connecting them to the firewall.&lt;BR /&gt;&lt;BR /&gt;This happened twice this year, with different PanOS releases.&lt;BR /&gt;&lt;BR /&gt;What I see in the Monitor &amp;gt; System is all the OSPF and OSPFv3 neighborships going down all at the same time, with no previous event leading into that. Opening the tech support bundle and looking at the logs, I can see routed starting to complain:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;2022-11-30 21:52:23.071 +0100 MON: status update md(235: 10.252.1.1 =&amp;gt; 10.252.1.2 =&amp;gt; 10.252.1.2) Failed&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="andale mono,times"&gt;[...other neighborships going down...]&lt;/FONT&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;**** AUDIT &lt;/SPAN&gt;&lt;SPAN&gt;0x3e01&lt;/SPAN&gt;&lt;SPAN&gt; - &lt;/SPAN&gt;&lt;SPAN&gt;91&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN&gt;0000&lt;/SPAN&gt;&lt;SPAN&gt;) **** I:1799db08 F:&lt;/SPAN&gt;&lt;SPAN&gt;00000002&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;qodmnmi.c&lt;/SPAN&gt; &lt;SPAN&gt;215&lt;/SPAN&gt;&lt;SPAN&gt; :at &lt;/SPAN&gt;&lt;SPAN&gt;21:52:34&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;30&lt;/SPAN&gt;&lt;SPAN&gt; November &lt;/SPAN&gt;&lt;SPAN&gt;2022&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN&gt;347569777&lt;/SPAN&gt;&lt;SPAN&gt; ms)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;OSPF &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt; An adjacency with a neighbor has gone down.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Resources associated with database exchange for this neighbor will be&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;freed.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Neighbor router ID &lt;/SPAN&gt;&lt;SPAN&gt;10&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;252&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Neighbor IP address &lt;/SPAN&gt;&lt;SPAN&gt;10&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;252&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Interface category network interface&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Interface neighbor IP addr &lt;/SPAN&gt;&lt;SPAN&gt;10&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;252&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt; i/f idx 0X00000000&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;BR /&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;**** AUDIT &lt;/SPAN&gt;&lt;SPAN&gt;0x3e01&lt;/SPAN&gt;&lt;SPAN&gt; - &lt;/SPAN&gt;&lt;SPAN&gt;210&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN&gt;0000&lt;/SPAN&gt;&lt;SPAN&gt;) **** I:1799db08 F:&lt;/SPAN&gt;&lt;SPAN&gt;00000002&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;qoamnfsa.c&lt;/SPAN&gt; &lt;SPAN&gt;768&lt;/SPAN&gt;&lt;SPAN&gt; :at &lt;/SPAN&gt;&lt;SPAN&gt;21:52:34&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;30&lt;/SPAN&gt;&lt;SPAN&gt; November &lt;/SPAN&gt;&lt;SPAN&gt;2022&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN&gt;347569780&lt;/SPAN&gt;&lt;SPAN&gt; ms)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;OSPF &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt; i/f idx 0X000000EC rtr ID &lt;/SPAN&gt;&lt;SPAN&gt;10&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;252&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt; IP addr &lt;/SPAN&gt;&lt;SPAN&gt;10&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;252&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt; neighbor FSM state has deteriorated.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Interface address = IP addr &lt;/SPAN&gt;&lt;SPAN&gt;10&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;252&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;OSPF link category = &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Is neighbor virtual? = &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;FSM input = QOAM_NBR_INACTIVITY_TMR (&lt;/SPAN&gt;&lt;SPAN&gt;13&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Old FSM state = AMB_OSPF_NBR_FULL (&lt;/SPAN&gt;&lt;SPAN&gt;8&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;New FSM state = AMB_OSPF_NBR_DOWN (&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;FSM action = I (&lt;/SPAN&gt;&lt;SPAN&gt;9&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Neighbor friend status = &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Number of neighbor events = &lt;/SPAN&gt;&lt;SPAN&gt;11&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT face="andale mono,times"&gt;&lt;SPAN&gt;Number of database exchange timeouts = &lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;...and some more PanOS-specific errors on dp0/mprelay for roughly the same timeframe:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&lt;FONT face="andale mono,times"&gt;2022-11-30 21:52:45.241 +0100 Error:&amp;nbsp; pan_mprelay_process_net_msg_queue(src_octeon/pan_mprelay_msg.c:676): Failed modify network message(type=bulk) sysd obj (QUEUE_DROP) slot(1)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&lt;FONT face="andale mono,times"&gt;2022-11-30 21:52:49.558 +0100 Fib entry update done&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&lt;FONT face="andale mono,times"&gt;2022-11-30 21:52:50.176 +0100 Error:&amp;nbsp; pan_mprelay_process_net_msg_queue(src_octeon/pan_mprelay_msg.c:676): Failed modify network message(type=bulk) sysd obj (QUEUE_DROP) slot(1)&amp;nbsp; (repeats 3987 times)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;Hence the question: &lt;EM&gt;is there any other tech-support log or timeframe I should look into, to have a clue about what's causing these issues?&lt;/EM&gt; e.g. I have events roughly 2 hours before in cp/mprelay, which look like a restart or config refresh, but I'm unsure they are related.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 16:35:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/networking-or-dataplane-apparent-reload-5200-w-10-1/m-p/523977#M108455</guid>
      <dc:creator>michelealbrigo</dc:creator>
      <dc:date>2022-12-13T16:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: Networking or Dataplane apparent reload (5200 w/10.1)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/networking-or-dataplane-apparent-reload-5200-w-10-1/m-p/524093#M108470</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44133"&gt;@michelealbrigo&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you check the DP CPU and packet buffers around the time of the interruption ? Spikes on DP CPU and buffers could impact OSPF and cause traffic disruption.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, the earliest 10.1.6 version dates from May this year (10.1.6-h6 from August) ... to rule out any bug in 10.1.6 or earlier I would strongly recommend upgrading to the current preferred release (10.1.8).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 14 Dec 2022 14:31:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/networking-or-dataplane-apparent-reload-5200-w-10-1/m-p/524093#M108470</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-12-14T14:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: Networking or Dataplane apparent reload (5200 w/10.1)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/networking-or-dataplane-apparent-reload-5200-w-10-1/m-p/524094#M108471</link>
      <description>&lt;P&gt;Hi and thank you for your reply. Upgrade to 10.1.8 is scheduled for this evening. I think you nailed the issue (i.e. who killed our OSPF):&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;2022-11-30 21:52:23.920 +0100 --- panio&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:Resource monitoring sampling data (per second):&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:CPU load sampling by group:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_lookup : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_fastpath : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_slowpath : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_forwarding : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_mgmt : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_ctrl : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:nac_result : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_np : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:dfa_result : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:module_internal : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:aho_result : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:zip_result : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:pktlog_forwarding : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:lwm : 0%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_host : 100%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:fpga_result : 0%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:CPU load (%) during last 15 seconds: &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:core 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 0 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:core 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100 100&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:core 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 100 100 100 100 100 100 100 100 0 0 0 0 0 0 0 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:Resource utilization (%) during last 15 seconds: &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:session:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:packet buffer:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;: 96 96 96 96 96 96 96 96 96 96 96 96 96 96 96&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The previous sampling (10 minutes before), which I won't post, sees all CPU core loads under 7%, and all zeros on packet buffers, which is consistent with the expected load for that timeframe (i.e. very low).&lt;BR /&gt;Any clue on how to further investigate the issue?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 14:55:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/networking-or-dataplane-apparent-reload-5200-w-10-1/m-p/524094#M108471</guid>
      <dc:creator>michelealbrigo</dc:creator>
      <dc:date>2022-12-14T14:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Networking or Dataplane apparent reload (5200 w/10.1)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/networking-or-dataplane-apparent-reload-5200-w-10-1/m-p/524101#M108472</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44133"&gt;@michelealbrigo&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hard to say from here on.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the top of my head I can think of the following reasons that can potentially cause high DP CPU usage ... but it can have a lot more root causes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Spike in SSL decryption sessions.&lt;/P&gt;
&lt;P&gt;Lot of ZIP processing (global counter: zip_process_total)&lt;/P&gt;
&lt;P&gt;High rate of Logging (global counter: log_loss_throttle)&lt;/P&gt;
&lt;P&gt;High rate of policy deny (global counter: flow_policy_deny)&lt;/P&gt;
&lt;P&gt;High rate of Fragments received (global counter: flow_ipfrag_recv)&lt;/P&gt;
&lt;P&gt;A sudden spike in CTD slowpath packets received will cause the device to backlog processing and cause high CPU (global counter: ctd_pkt_slowpath).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Packet rate is spiking (pkt_rcv and/or pkt_sent counters) caused by possible attack (DoS or zone protection could mitigate this) ?&lt;/P&gt;
&lt;P&gt;Spike in traffic that's not being offloaded.&lt;/P&gt;
&lt;P&gt;Spike in SMB traffic&lt;/P&gt;
&lt;P&gt;I'd also check interface bandwidth utilization to identify any source of high rate traffic - ACC and/or traffic logs could possibly help here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another useful command for determining the cause of high CPU usage is:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; debug dataplane pow performance&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This command returns the average processing time in micro seconds and the count of how many times this group/function was run, allowing you to identify what group or function is taking longer in cores to process.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 14 Dec 2022 15:46:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/networking-or-dataplane-apparent-reload-5200-w-10-1/m-p/524101#M108472</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-12-14T15:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Networking or Dataplane apparent reload (5200 w/10.1)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/networking-or-dataplane-apparent-reload-5200-w-10-1/m-p/524118#M108475</link>
      <description>&lt;P&gt;Thanks again, I can try a quick evaluation of the factors you pointed at:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Spike in SSL decryption sessions:&amp;nbsp;&lt;/STRONG&gt;we don't decrypt very much, so I'd exclude this&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Lot of ZIP processing (global counter: zip_process_total)&lt;/STRONG&gt;: see above, rate is consistently under 50 on the dp log&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;High rate of Logging (global counter: log_loss_throttle):&amp;nbsp;&lt;/STRONG&gt;we do some comprehensive logging, but within best practice recommendations (i.e. session end, and correct configuration of log destinations), and that counter rate is generally 0 (I have a spike of 700, but it's in another time frame and I think it might be related to a logserver restart)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;High rate of policy deny (global counter: flow_policy_deny):&lt;/STRONG&gt; THIS. See below.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;High rate of Fragments received (global counter: flow_ipfrag_recv):&amp;nbsp;&lt;/STRONG&gt;rate here is consistently low, peaks at around 200, but it's mostly in the 10-20 range&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;A sudden spike in CTD slowpath packets received will cause the device to backlog processing and cause high CPU (global counter: ctd_pkt_slowpath):&amp;nbsp;&lt;/STRONG&gt;I can't tell how many is too much, but definitely no spikes here around the issue (rate in the 5-8k zone)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Packet rate is spiking (pkt_rcv and/or pkt_sent counters) caused by possible attack (DoS or zone protection could mitigate this):&amp;nbsp;&lt;/STRONG&gt;this one, too.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Spike in traffic that's not being offloaded:&amp;nbsp;&lt;/STRONG&gt;can't tell very much about it...&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Spike in SMB traffic:&amp;nbsp;&lt;/STRONG&gt;unlikely in that timeframe, offices are already closed, backups aren't running yet. Same applies for bandwidth utilization, it wasn't a busy time.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Nonetheless, I have a spike in policy deny and a spike in packets received. By "spike" I mean an increase of at least 10x the baseline of the surrounding samples:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_policy_deny 1314 2795&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_policy_deny 1293 2727&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_policy_deny 1376 2813&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_policy_deny 145239 416157&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_policy_deny 1614 3260&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_policy_deny 1251 2673&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="andale mono,times"&gt;:flow_policy_deny 1181 2556&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="andale mono,times"&gt;:flow_np_pkt_rcv 10064 21412&lt;BR /&gt;:flow_np_pkt_rcv 10184 21485&lt;BR /&gt;:flow_np_pkt_rcv 12655 25879&lt;BR /&gt;:flow_np_pkt_rcv 158115 453051&lt;BR /&gt;:flow_np_pkt_rcv 24546 49587&lt;BR /&gt;:flow_np_pkt_rcv 22002 47012&lt;BR /&gt;:flow_np_pkt_rcv 22615 48950&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Our zone protection profiles are quite lax, by choice and lack of ability to handle them properly, so, unless the drops are due to the firewall "losing" all the internal networks, thus being unable to associate a destination zone, and ending up dropping the sessions (i.e. a closed loop cause/effect reference), a short-burst style DoS might be the case. Unluckily, the event already rolled out of my main log server, and I'm unable to investigate the traffic logs properly. I can see a lot of drops coming from an IP in my auto-populated blacklist, which includes PA's high-risk IP list. If I take another route within logs, I can see drops for a single IP reaching the export log limit of 65535 rows in just 2 minutes.&lt;BR /&gt;&lt;BR /&gt;I think I will have a long chat about those zone protection profiles with the rest of my team. Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 16:55:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/networking-or-dataplane-apparent-reload-5200-w-10-1/m-p/524118#M108475</guid>
      <dc:creator>michelealbrigo</dc:creator>
      <dc:date>2022-12-14T16:55:18Z</dc:date>
    </item>
  </channel>
</rss>

