<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access Slowness behind Palo Alto 3250 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/access-slowness-behind-palo-alto-3250/m-p/556944#M113037</link>
    <description>&lt;P&gt;Is all of your internet traffic being routed through zsaler? If so, how is a connection established, is it a single ipsec tunnel or is each client connecting independently. Is ssl decryption being applied&lt;/P&gt;</description>
    <pubDate>Thu, 07 Sep 2023 08:52:54 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2023-09-07T08:52:54Z</dc:date>
    <item>
      <title>Access Slowness behind Palo Alto 3250</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-slowness-behind-palo-alto-3250/m-p/556746#M113004</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have 3250 PA deployed in office, but we have interesting issue with traffic related to proxy particularly ZScaler/Internet access traffic (8080), we notice derogation or slowness in our access. We check the speed behind the router everything is OK, but the speed behind the PA is very slow. We have reviewed the CPU load and session for the past 10 weeks and we are consistent below average 25% CPU and below 4% average session. Check also the interface of all interfaces include the PA and Access switches no issue, BTW we have SNMP server monitoring network and all related to connection is pretty normal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I have notice one factor in ingress-backlogs: this session always present 24hrs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can someone help me to understand is this normal? or does it contribute to our issue?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have not tried killing or ending the session yet, I want to get other opinion first.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;USAGE - ATOMIC: 89.453125% TOTAL: 94.04296875%&lt;/P&gt;
&lt;P&gt;TOP SESSIONS:&lt;BR /&gt;SESS-ID PCT GRP-ID COUNT Special Notes&lt;BR /&gt;609463 89% flow_fastpath 883&lt;BR /&gt;flow_forwarding 33&lt;/P&gt;
&lt;P&gt;SESSION DETAILS&lt;BR /&gt;SESS-ID PROTO SZONE SRC SPORT DST DPORT IGR-IF EGR-IF TYPE APP&lt;BR /&gt;609463 6 Core_Zone 10.62.x.x 59980 10.77.x.x 445 ae2.309 ae2.41 FLOW ms-ds-smbv3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 12:55:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-slowness-behind-palo-alto-3250/m-p/556746#M113004</guid>
      <dc:creator>RUEL_Luchavez</dc:creator>
      <dc:date>2023-09-06T12:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: Access Slowness behind Palo Alto 3250</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-slowness-behind-palo-alto-3250/m-p/556944#M113037</link>
      <description>&lt;P&gt;Is all of your internet traffic being routed through zsaler? If so, how is a connection established, is it a single ipsec tunnel or is each client connecting independently. Is ssl decryption being applied&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 08:52:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-slowness-behind-palo-alto-3250/m-p/556944#M113037</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-09-07T08:52:54Z</dc:date>
    </item>
  </channel>
</rss>

