<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Possible solution to slow commit in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49402#M36391</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Funny how a PA-500 is so much slower than a PA-200 on commit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have exactly the same experience. As far as I can tell the PA-200 does have an SSD aka compactflash with very limited (16GB) capacity, but it's way faster than the PA-500 on commits (due to this ?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(edit) Also noticed that a PA-200 has much larger "management" memory available (2,6 GB instead of 1 GB for PA-500), could be another reason for the better performance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 May 2012 18:58:39 GMT</pubDate>
    <dc:creator>KP</dc:creator>
    <dc:date>2012-05-10T18:58:39Z</dc:date>
    <item>
      <title>Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49400#M36389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, regarding of the desperately slow commits in PA specially with a large number of rules and object. From our experiencie in other systems the rule shadow check is a very high CPU feature. It's sure that PA do a rule shadow and this it's in concordance with the fact that&amp;nbsp; as much rules and objects you have more slow is the commit (more combinations to check)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, could it be possible to have a check before commit to have the option of no use rule shadow?. Imagine that you are change only the name of object, probably you do not need check the shadows and I suppose the commit will be faster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone from PA could have the answer??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Samuel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 16:01:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49400#M36389</guid>
      <dc:creator>ssancho</dc:creator>
      <dc:date>2012-05-10T16:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49401#M36390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think it comes from there, with same rules and during idle times I have the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;PA-500&amp;nbsp; 52 rules , 12 minutes commit&lt;/LI&gt;&lt;LI&gt;PA-200 68 rules , 1 minute commit&lt;/LI&gt;&lt;LI&gt;PA-5050 285 rules, 45 seconds commit&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 16:07:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49401#M36390</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-05-10T16:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49402#M36391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Funny how a PA-500 is so much slower than a PA-200 on commit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have exactly the same experience. As far as I can tell the PA-200 does have an SSD aka compactflash with very limited (16GB) capacity, but it's way faster than the PA-500 on commits (due to this ?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(edit) Also noticed that a PA-200 has much larger "management" memory available (2,6 GB instead of 1 GB for PA-500), could be another reason for the better performance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 18:58:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49402#M36391</guid>
      <dc:creator>KP</dc:creator>
      <dc:date>2012-05-10T18:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49403#M36392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am investigating this too : my PA-500 swaps by 400MB, up to 800MB. A linux admin would be scared by this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try "show system resources" to have a look at your swap.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note : PA-2020 has 1GB of RAM too, I am going to install one next week and see if/how it's different.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 19:35:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49403#M36392</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-05-10T19:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49404#M36393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One additional info : If I'm interpreting right, what you see with 'show system resource' is that amount of memory assigned to the control-plane. The actual firewall has more memory, but what you see is the amount left after assigning some to the data-plane. Might be wrong about this, strictly reverse-engineering from my side.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 19:55:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49404#M36393</guid>
      <dc:creator>KP</dc:creator>
      <dc:date>2012-05-10T19:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49405#M36394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I think you are assuming right, note that Dataplane doesn't suffer any slowness, only Controlplane.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 19:58:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49405#M36394</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-05-10T19:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49406#M36395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What are the odds that PAN would support an upgrade of the RAM available in the units (thinking mainly of PA-500 and 2000 series who struggles with huge commit times)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specially when RAM memory is really cheap nowadays...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 20:18:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49406#M36395</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-10T20:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49407#M36396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you got data about PA-20XX&amp;nbsp; commit times? I am wondering if it's slow like 500 or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-5050 has 3GB of RAM, I just checked on mine&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 20:19:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49407#M36396</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-05-10T20:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49408#M36397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PA-20XX commit times are often on par with the other older platforms with less RAM and slower processors than the newer platforms (50XX and 200).&amp;nbsp; All of our newer platforms have followed all of the statements mentioned about the cost of memory and faster hardware and therefore, you will often see improvement in commit times.&amp;nbsp; With all of that said, commit times are very much determined by what changes are being made, by the amount of configuration you are commiting, the amount of logging, and the features running on the FW.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 20:58:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49408#M36397</guid>
      <dc:creator>Jamiefitzgerald</dc:creator>
      <dc:date>2012-05-10T20:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49409#M36398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As a note to essnet, PAN-OS will not recognize added RAM to the underlying OS.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 21:01:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49409#M36398</guid>
      <dc:creator>Jamiefitzgerald</dc:creator>
      <dc:date>2012-05-10T21:01:35Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49410#M36399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Two things:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-I can confirm to you that PA 2020 and PA2050 has the same commit times than PA-500. This week about 8 or 9 minutes in PA-2050 for each commit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-thanks jfitz-gerald for your help but what about the origin of this topic?, could it be posible to disable shadow rules check, could it be one of the reasons for this commit times?. We know that the time depends on the size of configuration, logging, number of objects and number of rules, but often this configurations are necesary and the perception of client is a very slow system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Samuel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 21:13:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49410#M36399</guid>
      <dc:creator>ssancho</dc:creator>
      <dc:date>2012-05-10T21:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49411#M36400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hah... our 4050s sometimes take up to 20 minutes to commit...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 22:59:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49411#M36400</guid>
      <dc:creator>dkhoe</dc:creator>
      <dc:date>2012-05-10T22:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49412#M36401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/people/jfitz-gerald" id="jive-72527,042,481,990,100,901" style="text-decoration: none; color: #555555; font-weight: bold; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-align: center; background-color: #f4f3f3;"&gt;jfitz-gerald&lt;/A&gt; I hope to get in touch with you very soon about this topic over phone with France PA representatives.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This place is a geek nest and I love it, I see that I am not alone and isolated about this problem despite what I was told and others also understood that RAM is &lt;SPAN style="text-decoration: underline;"&gt;probably&lt;/SPAN&gt; the problem may be among other things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note this is extremly problematic in production envrionnement : you get alerted of a problem, you login on FW (takes 2 minutes), you look at logs, make a change ( 10 minutes lost), make new tests, still doesn't work, new commit (10 more minutes). This is extremly true when you deploy a new box, like as a replacement to another vendor : you know that many rules will fail after migration, you have 1 or 2 hours deadline to make the move. 1 hour is just 3 or 4 commits max in my case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10 minutes is a hell of an eternity in production, in addition I don't get faster commits during idle or busy hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure you will provide us a solution, but I hope it won't take too long because I already had problems with top management who I had to explain what takes us so long to fix problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sell us PA-505, 2022 and 2055 models &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 23:01:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49412#M36401</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-05-10T23:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49413#M36402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;20XX series with faster disks , I tried WD Black Caviar 64 MB cache, help reducing commit times. Using a PA-2020 4.1.6 in production I've seen a mean reduction up to 1-2 mins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also rebooting the machine, better if in HA environment, can help specially when for some reasons commit take 10+ minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A suggestion for PAN: please upgrade hard disk and provide 2000 &amp;amp; 500 series with SSD, 200 &amp;amp; 5000 got it, why not the other series?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 23:32:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49413#M36402</guid>
      <dc:creator>NGS_SOC</dc:creator>
      <dc:date>2012-05-10T23:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Possible solution to slow commit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49414#M36403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you see an improvement due to the original fault where way to much swap is being used (reports in this forum of 400-800 MB of swap during commit).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When swap is being used the box will use the harddrive as "memory" and of course if you use an SSD instead the commit time will lower.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the proper fix is to not use swap at all - meaning increase amount of ram in the box so it wont swap at the first place (unless there is some software fix so the box wont use this much memory during commit).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps PA could address this with an upgrade kit which wont void the warranty?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The hardware needed (just an example to see the prices):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;KINGSTON 8GB 1333MHZ DDR3 CL9 HYPERX BLU (2X4GB)&lt;BR /&gt;~60 dollar + VAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAMSUNG 830 SERIES 256GB SSD SATA/600 MLC&lt;BR /&gt;~330 dollar + VAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(there is a 512GB model of above SSD for roughly 640 dollar + VAT)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So an upgrade for less than 500 dollar + VAT (including work) should be possible (or less than 800 dollar if we go for the 512GB model instead which I think should be preferred).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2012 06:39:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/possible-solution-to-slow-commit/m-p/49414#M36403</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-11T06:39:07Z</dc:date>
    </item>
  </channel>
</rss>

