<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Packet Drops under 3.1.8 / 3.1.9? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/packet-drops-under-3-1-8-3-1-9/m-p/44011#M32308</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;﻿This is more of an FYI than a question. I want to share what my company is going through so we can all learn from each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We monitor our network by sending out pings every 500ms. We have multiple ping sources going to scores of endpoints. Then, we correlate and report on the data. We've been doing this for years. We've got a good understanding of what "normal" looks like on the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We upgraded a PA-4020 (Threat Protection &amp;amp; URL Filtering, two vwires) from 3.1.4 to 3.1.8. Within hours, that firewall started experiencing "incidents". In each incident, the device would stop passing traffic for up to 15 seconds. Of course, the logs and counters don't show anything abnormal. Every few hours, the system would experience an incident. Sometimes at 03:00, but usually during business hours. It did seem to be somewhat load related. (High load on this box is a few hundred Mbit/sec)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Support didn't seem to believe us that this was a problem. After about a week / ten days, we gave up on getting support engaged to understand the problem, and we rolled back to 3.1.4. Everything has been fine since then.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Since then, we've got support engaged and looking at the problem. They're saying that there haven't been any fixes in 3.1.9 for issues like this. In other words, they're recommending we avoid 3.1.9 as we'll likely have the same problem.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is anyone else running these versions of code? Do you have good monitoring like this? If I gave you some scripts, would you let me know how it goes?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We do have 3.1.8 on over a dozen other 4020's and it is working fine. Very different traffic loads on those devices and no URL filtering.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We played with 4.0 for a bit... and then went back to 3.1 for stability. Don't even get me started on 4060's: The solution to one of my tickets is "Just keep rebooting until it works".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're seeing silent packet drops in 3.1.8 or 3.1.9, you're not the only one.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;This is cross posted to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://markjx.blogspot.com/2011/07/pan-silent-packet-drops-in-318.html"&gt;http://markjx.blogspot.com/2011/07/pan-silent-packet-drops-in-318.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Jul 2011 23:36:15 GMT</pubDate>
    <dc:creator>markjx</dc:creator>
    <dc:date>2011-07-11T23:36:15Z</dc:date>
    <item>
      <title>Packet Drops under 3.1.8 / 3.1.9?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-drops-under-3-1-8-3-1-9/m-p/44011#M32308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;﻿This is more of an FYI than a question. I want to share what my company is going through so we can all learn from each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We monitor our network by sending out pings every 500ms. We have multiple ping sources going to scores of endpoints. Then, we correlate and report on the data. We've been doing this for years. We've got a good understanding of what "normal" looks like on the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We upgraded a PA-4020 (Threat Protection &amp;amp; URL Filtering, two vwires) from 3.1.4 to 3.1.8. Within hours, that firewall started experiencing "incidents". In each incident, the device would stop passing traffic for up to 15 seconds. Of course, the logs and counters don't show anything abnormal. Every few hours, the system would experience an incident. Sometimes at 03:00, but usually during business hours. It did seem to be somewhat load related. (High load on this box is a few hundred Mbit/sec)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Support didn't seem to believe us that this was a problem. After about a week / ten days, we gave up on getting support engaged to understand the problem, and we rolled back to 3.1.4. Everything has been fine since then.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Since then, we've got support engaged and looking at the problem. They're saying that there haven't been any fixes in 3.1.9 for issues like this. In other words, they're recommending we avoid 3.1.9 as we'll likely have the same problem.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is anyone else running these versions of code? Do you have good monitoring like this? If I gave you some scripts, would you let me know how it goes?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We do have 3.1.8 on over a dozen other 4020's and it is working fine. Very different traffic loads on those devices and no URL filtering.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We played with 4.0 for a bit... and then went back to 3.1 for stability. Don't even get me started on 4060's: The solution to one of my tickets is "Just keep rebooting until it works".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're seeing silent packet drops in 3.1.8 or 3.1.9, you're not the only one.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;This is cross posted to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://markjx.blogspot.com/2011/07/pan-silent-packet-drops-in-318.html"&gt;http://markjx.blogspot.com/2011/07/pan-silent-packet-drops-in-318.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jul 2011 23:36:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-drops-under-3-1-8-3-1-9/m-p/44011#M32308</guid>
      <dc:creator>markjx</dc:creator>
      <dc:date>2011-07-11T23:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Drops under 3.1.8 / 3.1.9?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-drops-under-3-1-8-3-1-9/m-p/44012#M32309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: Courier New;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;set session tcp-reject-non-syn no&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Courier New;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;set deviceconfig setting session tcp-reject-non-syn no&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Courier New;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;set deviceconfig setting tcp drop-out-of-wnd no&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Set all the above settings and try out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BIJILESH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Aug 2011 07:00:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-drops-under-3-1-8-3-1-9/m-p/44012#M32309</guid>
      <dc:creator>sunilmathew</dc:creator>
      <dc:date>2011-08-18T07:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: Packet Drops under 3.1.8 / 3.1.9?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-drops-under-3-1-8-3-1-9/m-p/44013#M32310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Uh... We had already set these options before we deployed my 20 PAN's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MJ&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Aug 2011 12:16:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-drops-under-3-1-8-3-1-9/m-p/44013#M32310</guid>
      <dc:creator>markjx</dc:creator>
      <dc:date>2011-08-18T12:16:42Z</dc:date>
    </item>
  </channel>
</rss>

