<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pa-2020 and number of rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32106#M23537</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have PA-2020 and 160 rules. Management plane is slow in responding. Management CPU is often 98%. Commiting changes takes 10 minutes. From time to time first commit fails with error "&lt;SPAN&gt;Management server failed to send phase 1 to client websrvr&lt;/SPAN&gt;". What is going wrong? Too many rules affect performance?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Radoslaw&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Feb 2014 22:11:49 GMT</pubDate>
    <dc:creator>UMWL</dc:creator>
    <dc:date>2014-02-12T22:11:49Z</dc:date>
    <item>
      <title>Pa-2020 and number of rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32106#M23537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have PA-2020 and 160 rules. Management plane is slow in responding. Management CPU is often 98%. Commiting changes takes 10 minutes. From time to time first commit fails with error "&lt;SPAN&gt;Management server failed to send phase 1 to client websrvr&lt;/SPAN&gt;". What is going wrong? Too many rules affect performance?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Radoslaw&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Feb 2014 22:11:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32106#M23537</guid>
      <dc:creator>UMWL</dc:creator>
      <dc:date>2014-02-12T22:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Pa-2020 and number of rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32107#M23538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Radoslaw,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont think you have too many policy on this firewall. The Max numbers are given below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@21-PA-2020&amp;gt; show system state | match policy&lt;/P&gt;&lt;P&gt;cfg.general.max-cp-policy-rule: 1000&lt;/P&gt;&lt;P&gt;cfg.general.max-di-nat-policy-rule: 6000&lt;/P&gt;&lt;P&gt;cfg.general.max-dip-nat-policy-rule: 200&lt;/P&gt;&lt;P&gt;cfg.general.max-dos-policy-rule: 1000&lt;/P&gt;&lt;P&gt;cfg.general.max-nat-policy-rule: 1000&lt;/P&gt;&lt;P&gt;cfg.general.max-oride-policy-rule: 1000&lt;/P&gt;&lt;P&gt;cfg.general.max-pbf-policy-rule: 500&lt;/P&gt;&lt;P&gt;cfg.general.max-policy-rule: 10000&lt;/P&gt;&lt;P&gt;cfg.general.max-qos-policy-rule: 1000&lt;/P&gt;&lt;P&gt;cfg.general.max-si-nat-policy-rule: 1000&lt;/P&gt;&lt;P&gt;cfg.general.max-ssl-policy-rule: 1000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have custom signature/custom URL filtering configured on this firewall, It could take longer commit time than expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would request you to verify the management plane resources of this PA-2020 firewall with below mentioned command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show system resources follow&amp;nbsp;&amp;nbsp;&amp;nbsp; ------- Please verify if management server or any other daemon taking much CPU cycle or memory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the time being you can apply CLI command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;gt; debug software restart management-server&amp;nbsp; ----- It will reset the management-server process and it would not impact to your production traffic ( you will lost the SSH connection to the management-plane for few minute). I hope it will improve the commit time or response time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Feb 2014 00:06:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32107#M23538</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-13T00:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Pa-2020 and number of rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32108#M23539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will need to run show system resources and try to determine which process is responsible for the high cpu in the management plane.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer to this document for an overview.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4649" title="https://live.paloaltonetworks.com/docs/DOC-4649"&gt;https://live.paloaltonetworks.com/docs/DOC-4649&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Feb 2014 00:06:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32108#M23539</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-02-13T00:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Pa-2020 and number of rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32109#M23540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is related to a lack of resources for the mgmt plane. There is an upgrade kit available if needed.&lt;/P&gt;&lt;P&gt;This can be caused by a lot of things, a lot of User-ID that needs to be done, or even a lot of logging. If you have a few k of logs every minute then you'll notice slowness in the gui and high cpu, since it is the mgmt plane that handles all the logging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Mar 2014 11:54:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32109#M23540</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2014-03-14T11:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: Pa-2020 and number of rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32110#M23541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I've been told, PA does not offer an upgrade kit for the 2000 series...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This issue is also being discussed in &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/thread/10099" title="https://live.paloaltonetworks.com/thread/10099"&gt;https://live.paloaltonetworks.com/thread/10099&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Mar 2014 08:37:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32110#M23541</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2014-03-19T08:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Pa-2020 and number of rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32111#M23542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My bad, there is indeed only an upgrade kit for the PA-500 available&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Mar 2014 08:53:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32111#M23542</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2014-03-19T08:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: Pa-2020 and number of rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32112#M23543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The PA2000 series is a joke and everyone that bought PA2000s should have their gear automatically replaced with either PA500s or PA3000s. In my humble opinion. The performance numbers on our PA2050 never hit published specs, ever, with extensive testing I did with breaking Point. With a Breaking Point engineer present.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Mar 2014 15:08:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-2020-and-number-of-rules/m-p/32112#M23543</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-03-19T15:08:45Z</dc:date>
    </item>
  </channel>
</rss>

