<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Cache Usage Warning After Upgrade to PAN-OS 11.1.13-h1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-cache-usage-warning-after-upgrade-to-pan-os-11-1-13-h1/m-p/1250433#M126160</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220186"&gt;@khkim&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It’s difficult to pinpoint the exact cause without more logs, but I’ve personally seen this error triggered by two very specific scenarios:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've seen these warnings on PA-440 platforms.&amp;nbsp;&lt;SPAN&gt;The firewall was consistently triggering memory alerts because its configuration file size (30MB) exceeds 80% of the maximum recommended configuration size (35MB) for the PA-400 platform, indicating management plane stress rather than dataplane operational capacity issues.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In case of the PA-400 scenario there were several ways to reduce the configuration file size:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Doing a thorough audit of your firewall's configuration to identify and remove any unused or redundant elements. This is the most effective way to reduce the file size. Key areas to review include: &lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;Objects: Unused Address, Service, and Application objects or groups. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Policies: Disabled or obsolete Security, NAT, and QoS policies. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Profiles: Old or unattached Security Profiles (e.g., Antivirus, Anti-Spyware, URL Filtering). &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Log Forwarding: Obsolete Log Forwarding Profiles or assignments. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;The objective is to reduce the configuration size to a level comfortably below the 35 MB threshold. This stopped the alerts in the PA-400 scenario.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="8"&gt;I’ve also seen this on VM-Series firewalls deployed on unsupported instance types (for example, an r5.xlarge on AWS). While these instances might "work" initially, they aren't officially supported and could exhibit unexpected performance drops or memory alerts under load.&lt;/P&gt;
&lt;P data-path-to-node="8"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="9"&gt;You can verify your specific instance against the supported list here: &lt;A class="ng-star-inserted" href="https://docs.paloaltonetworks.com/vm-series/10-2/vm-series-performance-capacity/vm-series-performance-capacity/vm-series-on-aws-models-and-instances" target="_blank" rel="noopener"&gt;VM-Series on AWS Models and Instances&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I recommend opening a case with TAC for confirmation on what is causing the error in your case.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Mar 2026 09:18:33 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2026-03-18T09:18:33Z</dc:date>
    <item>
      <title>Policy Cache Usage Warning After Upgrade to PAN-OS 11.1.13-h1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-cache-usage-warning-after-upgrade-to-pan-os-11-1-13-h1/m-p/1250415#M126159</link>
      <description>&lt;P&gt;After upgrading to PAN-OS 11.1.13-h1, we started seeing the following warning log:&lt;BR /&gt;Warning: Policy cache usage is greater than 80 percent of the capacity&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have multiple firewalls in our environment, but this issue is only occurring on devices that were upgraded to version 11.1.13-h1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When checking with the following command:&lt;BR /&gt;&amp;gt; debug dataplane show cfg-memstat statistics&lt;BR /&gt;We see:&lt;BR /&gt;VSYS Config Allocator Usage: 51%&lt;BR /&gt;POLICY CACHE USAGE: 82%&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on this behavior, we would like to know if this is a known issue or bug specific to PAN-OS 11.1.13-h1.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 02:41:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-cache-usage-warning-after-upgrade-to-pan-os-11-1-13-h1/m-p/1250415#M126159</guid>
      <dc:creator>khkim</dc:creator>
      <dc:date>2026-03-18T02:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Cache Usage Warning After Upgrade to PAN-OS 11.1.13-h1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-cache-usage-warning-after-upgrade-to-pan-os-11-1-13-h1/m-p/1250433#M126160</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/220186"&gt;@khkim&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It’s difficult to pinpoint the exact cause without more logs, but I’ve personally seen this error triggered by two very specific scenarios:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've seen these warnings on PA-440 platforms.&amp;nbsp;&lt;SPAN&gt;The firewall was consistently triggering memory alerts because its configuration file size (30MB) exceeds 80% of the maximum recommended configuration size (35MB) for the PA-400 platform, indicating management plane stress rather than dataplane operational capacity issues.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In case of the PA-400 scenario there were several ways to reduce the configuration file size:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Doing a thorough audit of your firewall's configuration to identify and remove any unused or redundant elements. This is the most effective way to reduce the file size. Key areas to review include: &lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN&gt;Objects: Unused Address, Service, and Application objects or groups. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Policies: Disabled or obsolete Security, NAT, and QoS policies. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Profiles: Old or unattached Security Profiles (e.g., Antivirus, Anti-Spyware, URL Filtering). &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Log Forwarding: Obsolete Log Forwarding Profiles or assignments. &lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;The objective is to reduce the configuration size to a level comfortably below the 35 MB threshold. This stopped the alerts in the PA-400 scenario.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="8"&gt;I’ve also seen this on VM-Series firewalls deployed on unsupported instance types (for example, an r5.xlarge on AWS). While these instances might "work" initially, they aren't officially supported and could exhibit unexpected performance drops or memory alerts under load.&lt;/P&gt;
&lt;P data-path-to-node="8"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-path-to-node="9"&gt;You can verify your specific instance against the supported list here: &lt;A class="ng-star-inserted" href="https://docs.paloaltonetworks.com/vm-series/10-2/vm-series-performance-capacity/vm-series-performance-capacity/vm-series-on-aws-models-and-instances" target="_blank" rel="noopener"&gt;VM-Series on AWS Models and Instances&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I recommend opening a case with TAC for confirmation on what is causing the error in your case.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Kind regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2026 09:18:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-cache-usage-warning-after-upgrade-to-pan-os-11-1-13-h1/m-p/1250433#M126160</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2026-03-18T09:18:33Z</dc:date>
    </item>
  </channel>
</rss>

