<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Software packet buffer depletion in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/72755#M41177</link>
    <description>&lt;P&gt;We're currently observing something quite interesting:&lt;BR /&gt;On our highly oversized PA-5050 firewall, software packet buffer 0 is, for several hours a day exhausted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the platform (pair that runs in High Avalailability A/P):&lt;BR /&gt;family: 5000&lt;BR /&gt;model: PA-5050&lt;BR /&gt;sw-version: 7.0.4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the anomaly:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; debug dataplane pool statistics&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Software Pools&lt;/FONT&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;[ 0] software packet buffer 0 ( 512): 1/32768 0x8000000020c00680&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[ 1] software packet buffer 1 ( 1024): 23178/32768 0x8000000021c20780&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[ 2] software packet buffer 2 ( 2048): 31775/32768 0x8000000023c40880&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[ 3] software packet buffer 3 (33280): 24528/24576 0x8000000027c60980&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[ 4] software packet buffer 4 (66048): 304/304 0x8000000058878a80&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt; |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt; |&lt;/FONT&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;[17] FPTCP segs ( 16): 6703/49152 0x80000000d8f68a80&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The load on the firewall is minimal:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; show session info&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;--------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of sessions supported: 2000000&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active sessions: 38996&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active TCP sessions: 29985&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active UDP sessions: 8434&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active ICMP sessions: 273&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active BCAST sessions: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active MCAST sessions: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active predict sessions: 774&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Session table utilization: 1%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of sessions created since bootup: 355140861&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Packet rate: 16892/s&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Throughput: 54252 kbps&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;New connection establish rate: 760 cps&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;--------------------------------------------------------------------------------&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Anyone else seeing something similar ?&lt;/P&gt;
&lt;P&gt;(and yes, case has been opened with PAN-support)&lt;/P&gt;</description>
    <pubDate>Fri, 12 Feb 2016 10:21:37 GMT</pubDate>
    <dc:creator>Dulle</dc:creator>
    <dc:date>2016-02-12T10:21:37Z</dc:date>
    <item>
      <title>Software packet buffer depletion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/72755#M41177</link>
      <description>&lt;P&gt;We're currently observing something quite interesting:&lt;BR /&gt;On our highly oversized PA-5050 firewall, software packet buffer 0 is, for several hours a day exhausted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the platform (pair that runs in High Avalailability A/P):&lt;BR /&gt;family: 5000&lt;BR /&gt;model: PA-5050&lt;BR /&gt;sw-version: 7.0.4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the anomaly:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; debug dataplane pool statistics&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Software Pools&lt;/FONT&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;[ 0] software packet buffer 0 ( 512): 1/32768 0x8000000020c00680&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[ 1] software packet buffer 1 ( 1024): 23178/32768 0x8000000021c20780&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[ 2] software packet buffer 2 ( 2048): 31775/32768 0x8000000023c40880&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[ 3] software packet buffer 3 (33280): 24528/24576 0x8000000027c60980&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[ 4] software packet buffer 4 (66048): 304/304 0x8000000058878a80&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt; |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt; |&lt;/FONT&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;[17] FPTCP segs ( 16): 6703/49152 0x80000000d8f68a80&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The load on the firewall is minimal:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; show session info&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;--------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of sessions supported: 2000000&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active sessions: 38996&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active TCP sessions: 29985&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active UDP sessions: 8434&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active ICMP sessions: 273&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active BCAST sessions: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active MCAST sessions: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of active predict sessions: 774&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Session table utilization: 1%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Number of sessions created since bootup: 355140861&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Packet rate: 16892/s&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Throughput: 54252 kbps&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;New connection establish rate: 760 cps&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;--------------------------------------------------------------------------------&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Anyone else seeing something similar ?&lt;/P&gt;
&lt;P&gt;(and yes, case has been opened with PAN-support)&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2016 10:21:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/72755#M41177</guid>
      <dc:creator>Dulle</dc:creator>
      <dc:date>2016-02-12T10:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: Software packet buffer depletion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/72784#M41185</link>
      <description>&lt;P&gt;Hi Dulle,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems odd. What are the dataplane usage %s? Are they normal or high? Any particular process that is high?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; show running resource-monitor&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Might be worth rebooting the firewall/data plane to clear these out. Also worth an upgrade to the latest minor release but I suspect support can give you better assistance in findout out the root cause.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2016 16:58:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/72784#M41185</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-02-12T16:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: Software packet buffer depletion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/72855#M41206</link>
      <description>&lt;P&gt;Update:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Research by PAN-support revealed that this depletion in our case, is related to traffic with destination address 173.255.112.173 (stream.pushbullet.com/).&lt;BR /&gt;The application is classsified in the session table as 'pushbullet', then changes to 'websocket' and finishes off as 'web-browsing' when logged.&lt;/P&gt;
&lt;P&gt;The sessions are persistent throug the firewall even when the client is disconnected.&lt;/P&gt;
&lt;P&gt;Even if the number of sessions to stream.pushbullet.com are modest, it seems somehow to bleed out the 'software packet buffer 0'&lt;BR /&gt;If this occcurs,it did help in our case to run a 'clear session all filter destination 173.255.112.173'&lt;BR /&gt;Also if the depletion causes problems (if all software packet buffer 0-4 are depleted, possibly dataplane reset), create firewall rule denying traffic to 173.255.112.173.&lt;/P&gt;
&lt;P&gt;(Thanks a lot to PAN-support engineer Nikola for invaluable help)&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2016 10:58:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/72855#M41206</guid>
      <dc:creator>Dulle</dc:creator>
      <dc:date>2016-02-15T10:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Software packet buffer depletion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/74579#M41729</link>
      <description>&lt;P&gt;Some more information for those who might care:&lt;/P&gt;
&lt;P&gt;The problem is not resolved but it is apparent that it's related to the App 'Pushbullet' ( see&amp;nbsp;&lt;A href="http://www.pushbullet.com)" target="_blank"&gt;www.pushbullet.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the result of 3(!) users in our company running Pushbullet as an extention i Chrome browser (still on the PA-5050)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;FW(active)&amp;gt; debug dataplane pool statistics&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;DP dp0:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;Software Pools&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;[ 0] software packet buffer 0&amp;nbsp; (&amp;nbsp; 512):&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;FONT color="#FF0000"&gt;1/32768&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x8000000020c00680&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;[ 1] software packet buffer 1&amp;nbsp; ( 1024):&amp;nbsp;&amp;nbsp;&amp;nbsp; 17781/32768&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x8000000021c20780&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;[ 2] software packet buffer 2&amp;nbsp; ( 2048):&amp;nbsp;&amp;nbsp;&amp;nbsp; 31141/32768&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x8000000023c40880&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;[ 3] software packet buffer 3&amp;nbsp; (33280):&amp;nbsp;&amp;nbsp;&amp;nbsp; 24506/24576&amp;nbsp;&amp;nbsp; &amp;nbsp;0x8000000027c60980&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;[ 4] software packet buffer 4&amp;nbsp; (66048):&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 304/304&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x8000000058878a80&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;[17] FPTCP segs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (&amp;nbsp;&amp;nbsp; 16):&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;FONT color="#FF0000"&gt;1/49152&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0x80000000d8f68a80&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We play a game we call 'software buffer chicken' and see if the FPTCP pool&amp;nbsp;depletion can cause a dp0 reset.&lt;BR /&gt;The firewall chickes out, and seems to reset its pools. We win &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Also worth noting: the problem occurs only if you run &amp;nbsp;a decryption policy that the traffic hits.&lt;BR /&gt;(Hence the Forward Proxy TCP segs pool depeltion)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;(We now do a no_decrypt for traffiic to IP&amp;nbsp;173.255.112.173, the home of Pushbullet, to avoid trouble over the weekend....)&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2016 08:54:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/74579#M41729</guid>
      <dc:creator>Dulle</dc:creator>
      <dc:date>2016-03-11T08:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: Software packet buffer depletion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/74580#M41730</link>
      <description>&lt;P&gt;Thanks for follow up. Please tell me that you already updated to 7.0.5-h2, I see 7.0.4 in the first post?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;BR /&gt;&lt;BR /&gt;Luciano&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2016 09:02:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/74580#M41730</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2016-03-11T09:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: Software packet buffer depletion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/74588#M41732</link>
      <description>&lt;P&gt;Nah... Don't like the hotfix solutions, still 7.0.4.&lt;/P&gt;
&lt;P&gt;And since neither 7.0.5 or 7.0.5-h2 has any description of a fix for this particular...anomaly, we haven't bothered.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2016 10:44:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/74588#M41732</guid>
      <dc:creator>Dulle</dc:creator>
      <dc:date>2016-03-11T10:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: Software packet buffer depletion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/74621#M41741</link>
      <description>&lt;P&gt;Hi Dulle,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I may offer my opinion (IMHO): hotfix or not hotfix, this is regular update (it is called hotfix because it just patched up a thing or two on 7.0.5 that was already ready to go out). It does fix important issues that weren't described in much detail in release notes so that users that did not have a chance to update yet aren't fully exposed. Describing how you fixed the issue that isn't publicly known is particularly touchy subject, isn't it? If you are taking care of thousands and thousands of users as PAN - if this was academic discussion by all means I would like to see full details, but since we are dealing with real world and trying to protect people in real time - I can understand PAN reasons to disclose as little as possible at this time but publish patches. That being said, if vendor says something is critical, I patch (iPatch?), even my own phone &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Sat, 12 Mar 2016 07:41:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/software-packet-buffer-depletion/m-p/74621#M41741</guid>
      <dc:creator>Lucky</dc:creator>
      <dc:date>2016-03-12T07:41:35Z</dc:date>
    </item>
  </channel>
</rss>

