<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Increase Data plane CPU on PA-500 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/increase-data-plane-cpu-on-pa-500/m-p/44676#M32793</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have never had this problem so Im just guessing now &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to enable IDP for both directions (if you didnt already do so) along with antivirus controls, botnet detection, url categorization etc - simply enable all filtering features you can find along with logging for not only session end but also session start (the later I guess could saturate the mgmtplane before the dataplane).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then its a matter of pushing traffic... if possible you could record a pcap file and then replay it using tcpreplay:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tcpreplay.synfin.net/"&gt;http://tcpreplay.synfin.net/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: By the way according to a NSS Labs test enabling ALL features of PAN actually increased the throughput so I dunno... perhaps enabling just one feature will be worser for the dataplane than when everything is enabled? &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Mar 2012 21:31:27 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-03-12T21:31:27Z</dc:date>
    <item>
      <title>Increase Data plane CPU on PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/increase-data-plane-cpu-on-pa-500/m-p/44675#M32792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, every body!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used Palo Alto - 500&amp;nbsp; with version 4.0.1&lt;/P&gt;&lt;P&gt;On this device, Data plane CPU alway about 6-20%. I want to increase Data plane CPU on Pa-500 (4.0.1)&lt;/P&gt;&lt;P&gt;Please help me How to increase CPU up to 70-90% ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks all !!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 03:28:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/increase-data-plane-cpu-on-pa-500/m-p/44675#M32792</guid>
      <dc:creator>thenlee</dc:creator>
      <dc:date>2012-03-12T03:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: Increase Data plane CPU on PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/increase-data-plane-cpu-on-pa-500/m-p/44676#M32793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have never had this problem so Im just guessing now &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to enable IDP for both directions (if you didnt already do so) along with antivirus controls, botnet detection, url categorization etc - simply enable all filtering features you can find along with logging for not only session end but also session start (the later I guess could saturate the mgmtplane before the dataplane).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then its a matter of pushing traffic... if possible you could record a pcap file and then replay it using tcpreplay:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tcpreplay.synfin.net/"&gt;http://tcpreplay.synfin.net/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: By the way according to a NSS Labs test enabling ALL features of PAN actually increased the throughput so I dunno... perhaps enabling just one feature will be worser for the dataplane than when everything is enabled? &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 21:31:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/increase-data-plane-cpu-on-pa-500/m-p/44676#M32793</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-12T21:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Increase Data plane CPU on PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/increase-data-plane-cpu-on-pa-500/m-p/44677#M32794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply, &lt;A href="https://live.paloaltonetworks.com/people/mikand" id="jive-32451,975,960,496,462,901"&gt;mikand&lt;/A&gt; !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have never enable IDP before, I will try it.&lt;/P&gt;&lt;P&gt;Mgmt CPU on my device usually about 30-50% but Dataplane cpu only&amp;nbsp; 6-20%.&lt;/P&gt;&lt;P&gt;I think that mgmt cpu didn't depend on dataplane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2012 07:32:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/increase-data-plane-cpu-on-pa-500/m-p/44677#M32794</guid>
      <dc:creator>thenlee</dc:creator>
      <dc:date>2012-03-13T07:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Increase Data plane CPU on PA-500</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/increase-data-plane-cpu-on-pa-500/m-p/44678#M32795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats the idea of the mgmtplane vs dataplane in PAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The mgmtplane is a regular x86 cpu taking care of GUI, compiling configurations (when you click commit) and handle all the logs. Also for smaller models the mgmtplane will also take care of the on-the-fly generation of MITM certs for SSL-inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The dataplane is a fpga/asic (depending on box) where all the traffic is being handled (and for (I think) 5xxx models includes on-the-fly generation of MITM certs for SSL-inspection).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This gives that even during a DDoS situation where the dataplane is maxed out your GUI should work without problems (depending on your logsettings etc since all the logs that the dataplane pukes out will be handled by the mgmtplane if you have setup to log stuff).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With that said having a high "cpu utilization" for the dataplane isnt really an issue until it hits the 100% mark and latency will start to occur.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also the utilization doesnt seem to be linear either. Like if you with 2.500 concurrent sessions see 25% data-cpu it doesnt mean that the max limit will be 10.000 concurrent sessions but rather 20.000, 30.000 or so (just an example).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2012 10:27:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/increase-data-plane-cpu-on-pa-500/m-p/44678#M32795</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-13T10:27:06Z</dc:date>
    </item>
  </channel>
</rss>

