<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to find source of high open sessions and/or throughput in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-source-of-high-open-sessions-and-or-throughput/m-p/67541#M39582</link>
    <description>&lt;P&gt;So all new sessions last long and don't expire to get log into traffic log?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should enable syn cookies on zone protection profile. Then you have log when treshold is reached.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Monitor &amp;gt; App scope &amp;gt; Change monitor should show latest changes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create custom report to show packet count and if you order by quarter hour&amp;nbsp;to see if any anomalies.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Pan(w)achrome Chrome plugin shows really high overview in real time (source/destination physical/logical interface with packet/throughput count).&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 01 Nov 2015 20:56:20 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2015-11-01T20:56:20Z</dc:date>
    <item>
      <title>How to find source of high open sessions and/or throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-source-of-high-open-sessions-and-or-throughput/m-p/67501#M39559</link>
      <description>&lt;P&gt;If your Palo Alto firewall is experiencing an unusually high OPEN session count, and/or high throughput, what is the best way to determine the source or destination at the same time of the event?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have most of our security rules set to log at session end, so doing research on open sessions makes it a little harder. &amp;nbsp;I have confirmed that the ACC tab does not show data for open sessions either. &amp;nbsp;The Session Browser isn't too helpful because 1) you can't search by Start Time, 2) it only shows up to 2048 open sessions, 3) you can't export the results, 4) it's hard to pinpoint a specific source or destination IP.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 14:04:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-source-of-high-open-sessions-and-or-throughput/m-p/67501#M39559</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2015-10-30T14:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to find source of high open sessions and/or throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-source-of-high-open-sessions-and-or-throughput/m-p/67541#M39582</link>
      <description>&lt;P&gt;So all new sessions last long and don't expire to get log into traffic log?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should enable syn cookies on zone protection profile. Then you have log when treshold is reached.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Monitor &amp;gt; App scope &amp;gt; Change monitor should show latest changes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can create custom report to show packet count and if you order by quarter hour&amp;nbsp;to see if any anomalies.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Pan(w)achrome Chrome plugin shows really high overview in real time (source/destination physical/logical interface with packet/throughput count).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2015 20:56:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-source-of-high-open-sessions-and-or-throughput/m-p/67541#M39582</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-11-01T20:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to find source of high open sessions and/or throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-source-of-high-open-sessions-and-or-throughput/m-p/67597#M39605</link>
      <description>&lt;P&gt;I feel your pain, live with logging at session end the session table is your only options.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At times when we have had recurring issues like this we add log at session start to the most likely rule candidates based on the post event logging that we do have. &amp;nbsp;These are then much easier to filter when it comes around the next time.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2015 12:39:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-source-of-high-open-sessions-and-or-throughput/m-p/67597#M39605</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-11-03T12:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to find source of high open sessions and/or throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-source-of-high-open-sessions-and-or-throughput/m-p/152046#M50304</link>
      <description>&lt;P&gt;I need to resurrect this issue back from the dead.&amp;nbsp; We monitor our PA's with SNMP, and when the Session Count and/or Connection Rate increases to a number above normal, it's always a struggle to find the source of the problem using the PA interface.&amp;nbsp; Anyone have any tips?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's an example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our SNMP monitoring tool clearly shows a spike/hump in Open (TCP) Sessions...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="open-sessions-snmp.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8733iE6F1270FCF8B4520/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="open-sessions-snmp.PNG" alt="open-sessions-snmp.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The ACC tab does not reveal that there were any indications of a spike in traffic.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="open-sessions-dst-ip.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8734i1174F3601DC95051/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="open-sessions-dst-ip.PNG" alt="open-sessions-dst-ip.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="open-sessions-src-ip.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8735i64E55630D1BE4313/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="open-sessions-src-ip.PNG" alt="open-sessions-src-ip.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="open-sessions-app-usage.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/8736i381D7563CAD1D3EB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="open-sessions-app-usage.PNG" alt="open-sessions-app-usage.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 19:07:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-source-of-high-open-sessions-and-or-throughput/m-p/152046#M50304</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2017-04-10T19:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to find source of high open sessions and/or throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-source-of-high-open-sessions-and-or-throughput/m-p/156884#M51500</link>
      <description>&lt;P&gt;We have the same issue with PA-5050 v7.1.7. Monitoring through SNMP shows incorrect session values that do not match the ones shown by the firewall on CLI. It seems a bug with the&amp;nbsp;panSessionActive OID.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 12:23:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-source-of-high-open-sessions-and-or-throughput/m-p/156884#M51500</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-05-16T12:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to find source of high open sessions and/or throughput</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-source-of-high-open-sessions-and-or-throughput/m-p/157159#M51568</link>
      <description>&lt;P&gt;I am thinking to setup a netflow collector.&amp;nbsp; I am hoping Netflow may provide a closer to "real time" usage.&amp;nbsp; Any comments or suggestion on netflow ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;E&lt;/P&gt;</description>
      <pubDate>Thu, 18 May 2017 10:59:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-find-source-of-high-open-sessions-and-or-throughput/m-p/157159#M51568</guid>
      <dc:creator>nextgenhappines</dc:creator>
      <dc:date>2017-05-18T10:59:21Z</dc:date>
    </item>
  </channel>
</rss>

