<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Performance Problem with PA 500 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/performance-problem-with-pa-500/m-p/2321#M1716</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We need to check the firewall while the problem occurs, just to confirm if the PAN is causing the latency. Could you please analyze the ACC report during that time, anything looking abnormal..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 16 Feb 2014 05:50:50 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-02-16T05:50:50Z</dc:date>
    <item>
      <title>Performance Problem with PA 500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/performance-problem-with-pa-500/m-p/2318#M1713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I recently upgraded my bandwidth to fiber with my provider.&amp;nbsp; They added a router in the mix that was not there.&amp;nbsp; It has an external IP and and internal IP address.&amp;nbsp; The old setup only had an external IP (which is the IP that was configured in my firewall natting rules.)&amp;nbsp; My upload speed is around 90mb, but the download speed is not even 5mb.&amp;nbsp; .&amp;nbsp; We set all settings as the isp requested.&amp;nbsp; 100mbps ad Full Duplex, on the firewall and switch.&amp;nbsp; The path is. Fiber comes in to ISP Switch --&amp;gt; ISP Router --&amp;gt; Juniper Switch --&amp;gt; Firewall.&lt;/P&gt;&lt;P&gt;After trying everything we could think of I took the main PA500 offline and brought the HA1 online to take over.&amp;nbsp; Speeds hit 75-80 mb both ways.&amp;nbsp; This lasted a few hours until downloads started dragging again.&amp;nbsp;&amp;nbsp; I cleared the logs and speeds shot back up.&amp;nbsp; We are able to isolate the problem in the firewall.&amp;nbsp; What is causing my performance issues.&amp;nbsp; The HA is configured exactly like the primary, which is still offline.&amp;nbsp; All ideas are appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Feb 2014 19:18:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/performance-problem-with-pa-500/m-p/2318#M1713</guid>
      <dc:creator>MemphisBrothers</dc:creator>
      <dc:date>2014-02-15T19:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Performance Problem with PA 500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/performance-problem-with-pa-500/m-p/2319#M1714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using any specific protocol to measure the speed or just using free tools, i.e. speedtest.net...?&lt;/P&gt;&lt;P&gt;The first step is to isolate where the performance issue is occurring due to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Data Plane (DP) CPU&lt;/P&gt;&lt;P&gt;Packet Buffers&lt;/P&gt;&lt;P&gt;Session&lt;/P&gt;&lt;P&gt;Management Plane (MP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Most handy command&lt;/SPAN&gt; will be&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; :&lt;/SPAN&gt;PAN&amp;gt; &amp;gt; show system statistics session&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;show&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;running&lt;/SPAN&gt;&lt;/SPAN&gt; resource-monitor&lt;/P&gt;&lt;P&gt;a. Check the CPU load during the last 60 seconds. If any number is at or close to 100, then high CPU is likely the cause of the performance issue.&lt;/P&gt;&lt;P&gt;b. Check the "packet buffer" and "packet descriptor" sections. If any number is at or close to 100, then the issue is likely caused by running out of packet buffers.&lt;/P&gt;&lt;P&gt;c. Check the session section. If any number is close to or above 80, then the performance issue is most likely session related.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Few more commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;debug&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;dataplane&lt;/SPAN&gt;&lt;/SPAN&gt; pool statistics&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;show&lt;/SPAN&gt;&lt;/SPAN&gt; session info&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Feb 2014 20:47:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/performance-problem-with-pa-500/m-p/2319#M1714</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-15T20:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: Performance Problem with PA 500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/performance-problem-with-pa-500/m-p/2320#M1715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using a few different web sites to test speed, the same ones the ISP uses.&amp;nbsp; You know how they are, We can see the router and are sending 100 mgs so it must be on your end.Event they care not seeing 100 mgs which is what the fiber is supposed to be hitting.. I will test the commands you submitted.&amp;nbsp; After further measuring throughout today we are averaging 8&lt;STRONG&gt;0-85.&amp;nbsp; &lt;/STRONG&gt;Is it possible something has stabilize? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Feb 2014 03:02:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/performance-problem-with-pa-500/m-p/2320#M1715</guid>
      <dc:creator>MemphisBrothers</dc:creator>
      <dc:date>2014-02-16T03:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Performance Problem with PA 500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/performance-problem-with-pa-500/m-p/2321#M1716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We need to check the firewall while the problem occurs, just to confirm if the PAN is causing the latency. Could you please analyze the ACC report during that time, anything looking abnormal..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Feb 2014 05:50:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/performance-problem-with-pa-500/m-p/2321#M1716</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-16T05:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Performance Problem with PA 500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/performance-problem-with-pa-500/m-p/2322#M1717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with Hulk that you will need to gather data when the issue is occurring.&amp;nbsp; The top candidates for me would be cpu issues or resource exhaustion.&amp;nbsp; These are checked with:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;show running resource-monitor&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;debug dataplane pool statistics&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;On possible cause of these issues could be a threat or a ddos attack.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Another good test would be if you can get a laptop into that on the Juniper switch between the ISP router and the Palo Alto if an address is available.&amp;nbsp; Then run the download test from here during the issue.&amp;nbsp; This will eliminate the PA from the loop and do a test during the incident for possible outside influences or a transient ISP issue that they don't see because it is gone when they investigate but there during your problems.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Feb 2014 22:36:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/performance-problem-with-pa-500/m-p/2322#M1717</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-02-16T22:36:33Z</dc:date>
    </item>
  </channel>
</rss>

