<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Syslog issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/40386#M29642</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;has anyone experienced any issue with high amount of traffic sent to a Syslog server by PAN device, when updating from 3.0.8 to 3.1?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to be a bug (or a very strange beahvior) introduced in 3.1 release that cause many logs generated by sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are in trouble with some customers that disabled syslog log forwarding to preserve the syslog server (flooded by pan device).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We already opened a case (22118) in October but we are waiting for a response by PAN support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Nov 2010 18:54:10 GMT</pubDate>
    <dc:creator>migration</dc:creator>
    <dc:date>2010-11-30T18:54:10Z</dc:date>
    <item>
      <title>Syslog issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/40386#M29642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;has anyone experienced any issue with high amount of traffic sent to a Syslog server by PAN device, when updating from 3.0.8 to 3.1?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to be a bug (or a very strange beahvior) introduced in 3.1 release that cause many logs generated by sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are in trouble with some customers that disabled syslog log forwarding to preserve the syslog server (flooded by pan device).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We already opened a case (22118) in October but we are waiting for a response by PAN support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Nov 2010 18:54:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/40386#M29642</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2010-11-30T18:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/40387#M29643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I checked your referenced case and it was updated today with the following explanation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Engineering has informed us that this is expected behavior on 3.1.x and was due to a change in behavior in how syslog sessions are generated from PanOS 3.0.x to 3.1.x. In PanOS 3.0.x syslog sessions used the same source port, whereas syslog sessions in PanOS 3.1.x use different source ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The result of using the same source port (PanOS 3.0.x) in the syslog session could result in the downstream firewall resuing the same session for the syslog messages. The result of using a different source port (PanOS 3.1.x) will result in the downstream firewall having to create a new session for each new syslog message, which is why you were seeing a higher number of syslog sessions originating from the PAN firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Nov 2010 23:51:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/syslog-issue/m-p/40387#M29643</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2010-11-30T23:51:10Z</dc:date>
    </item>
  </channel>
</rss>

