<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic High Dataplan CPU PA2050-4.1.6 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/high-dataplan-cpu-pa2050-4-1-6/m-p/24697#M17994</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have only 28,000 active session at this time, which isn't a lot, and my CPU is roughly between 70-80% constantly.&amp;nbsp; We are in our summer semester at school which doesn't have a lot of users on our network. I am nervous when people return in the fall they will be greated with slow internet and possibly crash the Palo Alto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are running two Palo-Alto's both running 4.1.6 in Active/Active mode behind ASA 5580's.&amp;nbsp; The only action the PA's are taking is security policies.&amp;nbsp; No QoS, NAT, DLP, or any other process that would require high processing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My current rules are as follows:&lt;/P&gt;&lt;P&gt;Servers-IN: outside &amp;gt; inside servers allow - no filtering and no server response inspection&lt;/P&gt;&lt;P&gt;Servers: inside servers &amp;gt; outside&amp;nbsp; allow - no filtering and no server response inspection&lt;/P&gt;&lt;P&gt;BLOCKING: any to any Deny - deny any P2P applications&lt;/P&gt;&lt;P&gt;Data-Traffic inside &amp;gt; outside - allow - scanning for URL, Malware, Virus &lt;/P&gt;&lt;P&gt;Data-Traffic outside &amp;gt; inside - allow - scanning for URL, Malware, Virus&lt;/P&gt;&lt;P&gt;Student-Wireless student-wireless &amp;gt; outside - allow - scanning for URL, malware, virus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was running 4.1.2 and had 100% CPU which was crashing my PA and after digging in the forums found it was a software bug and upgraded to 4.1.6.&amp;nbsp; I hope this is a bug as my max sessions shows over 220,000. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. I have read the other threads regarding this issue, but they were on 4.1.2 which had a known bug.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Jun 2012 17:18:02 GMT</pubDate>
    <dc:creator>u10723</dc:creator>
    <dc:date>2012-06-12T17:18:02Z</dc:date>
    <item>
      <title>High Dataplan CPU PA2050-4.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/high-dataplan-cpu-pa2050-4-1-6/m-p/24697#M17994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have only 28,000 active session at this time, which isn't a lot, and my CPU is roughly between 70-80% constantly.&amp;nbsp; We are in our summer semester at school which doesn't have a lot of users on our network. I am nervous when people return in the fall they will be greated with slow internet and possibly crash the Palo Alto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are running two Palo-Alto's both running 4.1.6 in Active/Active mode behind ASA 5580's.&amp;nbsp; The only action the PA's are taking is security policies.&amp;nbsp; No QoS, NAT, DLP, or any other process that would require high processing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My current rules are as follows:&lt;/P&gt;&lt;P&gt;Servers-IN: outside &amp;gt; inside servers allow - no filtering and no server response inspection&lt;/P&gt;&lt;P&gt;Servers: inside servers &amp;gt; outside&amp;nbsp; allow - no filtering and no server response inspection&lt;/P&gt;&lt;P&gt;BLOCKING: any to any Deny - deny any P2P applications&lt;/P&gt;&lt;P&gt;Data-Traffic inside &amp;gt; outside - allow - scanning for URL, Malware, Virus &lt;/P&gt;&lt;P&gt;Data-Traffic outside &amp;gt; inside - allow - scanning for URL, Malware, Virus&lt;/P&gt;&lt;P&gt;Student-Wireless student-wireless &amp;gt; outside - allow - scanning for URL, malware, virus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was running 4.1.2 and had 100% CPU which was crashing my PA and after digging in the forums found it was a software bug and upgraded to 4.1.6.&amp;nbsp; I hope this is a bug as my max sessions shows over 220,000. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. I have read the other threads regarding this issue, but they were on 4.1.2 which had a known bug.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 17:18:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/high-dataplan-cpu-pa2050-4-1-6/m-p/24697#M17994</guid>
      <dc:creator>u10723</dc:creator>
      <dc:date>2012-06-12T17:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: High Dataplan CPU PA2050-4.1.6</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/high-dataplan-cpu-pa2050-4-1-6/m-p/24698#M17995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes there are cases where large data transfers that are being scanned can cause high CPU. You can use ACC and 'Sort By: Bytes' to find the application pushing through the most data. If there is nothing obvious, I would recommend opening a case with your support team so we can take a deep dive through the resource monitor logs and other data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 18:52:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/high-dataplan-cpu-pa2050-4-1-6/m-p/24698#M17995</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2012-06-12T18:52:45Z</dc:date>
    </item>
  </channel>
</rss>

