<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Frequent Running Of AddrObjRefresh Blocking Commits? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6906#M5089</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;I'm also pretty sure that disabling the "AD" profile will sort things out, but that's a test for Monday unless there's a CLI command along the lines of "commit when you next have a chance to do so" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;There are two LDAP server profiles, but only one is enabled (the Active Directory one). I'd be mildly surprised if there are network issues between either PA-5060 and the relevant AD server as although they're on different VLANs, there not a great deal of network between them. But I'd not be very surprised to find our Active Directory is in a bit of a state - a certain well known Python script that exports the binary database (1.6Gbytes!) to a text version took over a week to run just before Xmas.&lt;/P&gt;&lt;P&gt;I'll raise a support call with our reseller and mention 225414.&lt;/P&gt;&lt;P&gt;A short extract from the output of &lt;EM&gt;tail follow yes mp-log ms.log&lt;/EM&gt;:-&lt;/P&gt;&lt;PRE&gt;2015-01-11 07:38:41.515 +0000 device server refresh triggered via sysd
2015-01-11 07:38:41.515 +0000 Aborting. Another refresh in progress2015-01-11 07:38:42.162 +0000 client useridd disabled/restarted
2015-01-11 07:38:44.171 +0000 client useridd enabled 
2015-01-11 07:38:44.171 +0000 device server refresh triggered via sysd
2015-01-11 07:38:44.172 +0000 Aborting. Another refresh in progress2015-01-11 07:38:44.823 +0000 client useridd disabled/restarted
2015-01-11 07:38:45.579 +0000 client device reported Phase 1 was SUCCESSFUL
2015-01-11 07:38:46.842 +0000 client useridd enabled 
2015-01-11 07:38:46.843 +0000 device server refresh triggered via sysd
2015-01-11 07:38:46.843 +0000 dnscfgmod: Main refresh function: (unknown)
2015-01-11 07:38:46.849 +0000 dnscfgmod:Fqdn refresh job 14006 scheduled
2015-01-11 07:38:47.503 +0000 client useridd disabled/restarted
2015-01-11 07:38:49.510 +0000 client useridd enabled 
2015-01-11 07:38:49.511 +0000 device server refresh triggered via sysd
2015-01-11 07:38:49.511 +0000 Aborting. Another refresh in progress2015-01-11 07:38:50.187 +0000 client useridd disabled/restarted
2015-01-11 07:38:52.189 +0000 client useridd enabled 
2015-01-11 07:38:52.190 +0000 device server refresh triggered via sysd
2015-01-11 07:38:52.190 +0000 Aborting. Another refresh in progress2015-01-11 07:38:52.844 +0000 client useridd disabled/restarted
&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 11 Jan 2015 08:13:02 GMT</pubDate>
    <dc:creator>MikeMeredith</dc:creator>
    <dc:date>2015-01-11T08:13:02Z</dc:date>
    <item>
      <title>Frequent Running Of AddrObjRefresh Blocking Commits?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6904#M5087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm new here, so will probably be asking lots of dumb questions ... but hopefully relatively interesting dumb questions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently running PANOS 6.0.7 on a pair of PA-5060s (active-passive). Not currently live (switchover day is 17th January), and we're considering upgrading to 6.1.1 next week. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recently (last few days) ran into an issue whereby configuration commits are being blocked ("&lt;SPAN style="color: #222222; font-family: Tahoma, Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ebedee;"&gt;Another commit/validate is in progress. Please try again later"). &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I can work around this by doing a graceful reboot of our pair of PA-5060s but this seems a little extreme and I thought I would dig into it a bit deeper (and raise a support call). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only significant change recently (did I hear "Yeah! Right!" from the hecklers at the back?), was the addition of one of our Active Directory servers to Device-&amp;gt; User Identification -&amp;gt; Group Map Settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I've been able to figure out on my own was that there seems to be a job (&lt;EM&gt;show jobs all&lt;/EM&gt;) called "AddrObjRefresh" that seems to be kicking off every 10 seconds or so :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enqueued&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp; Status Result Completed &lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;2015/01/10 14:54:20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8290&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACT&amp;nbsp;&amp;nbsp; PEND&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0%&lt;/P&gt;&lt;P&gt;2015/01/10 14:54:09&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8289&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:54:19&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:53:59&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8288&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:54:08&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:53:48&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8287&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:53:58&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:53:38&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8286&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:53:47&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:53:27&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8285&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:53:37&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:53:17&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8284&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:53:26&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:53:06&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8283&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:53:16&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:52:56&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8282&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:53:05&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:52:45&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8281&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:52:55&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:52:35&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8280&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:52:44&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:52:24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8279&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:52:34&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:52:13&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8278&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:52:23&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:52:03&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8277&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:52:12&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:51:52&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8276&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:52:02&amp;nbsp; &lt;/P&gt;&lt;P&gt;2015/01/10 14:51:42&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8275&amp;nbsp;&amp;nbsp; AddrObjRefresh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FIN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK 14:51:51&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now for some questions :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Would you think that this might be what is interfering with our commit issue?&lt;/LI&gt;&lt;LI&gt;Is running AddrObjRefresh so frequently a normal thing? If not, is there anything I can do to diagnose what it is trying to do?&lt;/LI&gt;&lt;LI&gt;Is it possible/sensible to try and temporarily stop the AddrObjRefresh job from being scheduled?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Please be gentle: I'm a clueless newbie &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Jan 2015 15:14:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6904#M5087</guid>
      <dc:creator>MikeMeredith</dc:creator>
      <dc:date>2015-01-10T15:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: Frequent Running Of AddrObjRefresh Blocking Commits?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6905#M5088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;MikeMeredith,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are no 'dumb' questions. We all start somewhere, so no worries!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're on the right path with checking the jobs. Good work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you run the following command in the CLI, via SSH session, and log the session output to a file?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;'tail follow yes mp-log ms.log'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will show you the output from the ms.log management log file. This may show us some more details about what is going on when these &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;AddrObjRefresh jobs kick off.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;I'm referencing a very similar case here, with a pair of 5000 series having the exact same issue. (225414)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;They also had setup User-ID recently and experienced the same behavior, so this could be the same issue, or very close.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;How many profiles were setup for User-ID (ldap, etc) ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;In their scenario, the firewall was having trouble communicating to the LDAP server, due to other network issues, therefore user-id was taking up more cpu/ram than expected and constantly refreshing as it attempted to pull the group information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;I will bet you $100 that if you were to disable the recent changes with User-ID and the server profiles, the issue would stop occurring. If you get the chance, please try this out and verify while it is not in production. This will help narrow down the issue. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Let me know and we can go from there,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks!&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Jan 2015 22:42:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6905#M5088</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2015-01-10T22:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Frequent Running Of AddrObjRefresh Blocking Commits?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6906#M5089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;I'm also pretty sure that disabling the "AD" profile will sort things out, but that's a test for Monday unless there's a CLI command along the lines of "commit when you next have a chance to do so" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;There are two LDAP server profiles, but only one is enabled (the Active Directory one). I'd be mildly surprised if there are network issues between either PA-5060 and the relevant AD server as although they're on different VLANs, there not a great deal of network between them. But I'd not be very surprised to find our Active Directory is in a bit of a state - a certain well known Python script that exports the binary database (1.6Gbytes!) to a text version took over a week to run just before Xmas.&lt;/P&gt;&lt;P&gt;I'll raise a support call with our reseller and mention 225414.&lt;/P&gt;&lt;P&gt;A short extract from the output of &lt;EM&gt;tail follow yes mp-log ms.log&lt;/EM&gt;:-&lt;/P&gt;&lt;PRE&gt;2015-01-11 07:38:41.515 +0000 device server refresh triggered via sysd
2015-01-11 07:38:41.515 +0000 Aborting. Another refresh in progress2015-01-11 07:38:42.162 +0000 client useridd disabled/restarted
2015-01-11 07:38:44.171 +0000 client useridd enabled 
2015-01-11 07:38:44.171 +0000 device server refresh triggered via sysd
2015-01-11 07:38:44.172 +0000 Aborting. Another refresh in progress2015-01-11 07:38:44.823 +0000 client useridd disabled/restarted
2015-01-11 07:38:45.579 +0000 client device reported Phase 1 was SUCCESSFUL
2015-01-11 07:38:46.842 +0000 client useridd enabled 
2015-01-11 07:38:46.843 +0000 device server refresh triggered via sysd
2015-01-11 07:38:46.843 +0000 dnscfgmod: Main refresh function: (unknown)
2015-01-11 07:38:46.849 +0000 dnscfgmod:Fqdn refresh job 14006 scheduled
2015-01-11 07:38:47.503 +0000 client useridd disabled/restarted
2015-01-11 07:38:49.510 +0000 client useridd enabled 
2015-01-11 07:38:49.511 +0000 device server refresh triggered via sysd
2015-01-11 07:38:49.511 +0000 Aborting. Another refresh in progress2015-01-11 07:38:50.187 +0000 client useridd disabled/restarted
2015-01-11 07:38:52.189 +0000 client useridd enabled 
2015-01-11 07:38:52.190 +0000 device server refresh triggered via sysd
2015-01-11 07:38:52.190 +0000 Aborting. Another refresh in progress2015-01-11 07:38:52.844 +0000 client useridd disabled/restarted
&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Jan 2015 08:13:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6906#M5089</guid>
      <dc:creator>MikeMeredith</dc:creator>
      <dc:date>2015-01-11T08:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: Frequent Running Of AddrObjRefresh Blocking Commits?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6907#M5090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;MikeMeredith,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're welcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your log output matches the same errors referenced from the ms.log file in the case I mentioned, so it looks like this may be the same issue after all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to relate their solution to our situation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While raising a support call, please reference the output from ms.log, along with generating a TechSupport file for them to look at.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specifically we are looking to see if the RAM/CPU usage of the process 'useridd' is abnormally high.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you do a 'show system info' and past the output? What is the uptime?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know this sounds like a cliche` response, but have you rebooted the device since this started happening? Perhaps something is just hanging up in the management-plane, but that would be too easy. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mentioned this is not in production yet, but have you been authenticating many users across the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you pulling all the groups from the AD or just some of them? How many groups are we talking about the firewall pulling/mapping ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the previous scenario, the useridd process was being 'oversubscribed'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can be potentially mitigated by limiting what groups the firewall will try to map and configuring the access list for the zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are headed the right direction here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know,&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EDIT: I'm unaware of a commit type where we can do that, but it would be highly convenient, right? :smileysilly:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Jan 2015 09:06:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6907#M5090</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2015-01-11T09:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Frequent Running Of AddrObjRefresh Blocking Commits?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6908#M5091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll get onto all the necessary details tomorrow when I log a call with support. But some quick responses :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Yes the useridd process is hogging cpu at times (&lt;EM&gt;show system resources follow&lt;/EM&gt; ("top" is quicker to type) shows useridd at 99% often).&lt;/LI&gt;&lt;LI&gt;Can't list the groups through the firewall presently (I get an error), but there's a fair few - I recall seeing a figure of 3,000 but don't quote me on that.&lt;/LI&gt;&lt;LI&gt;Yes the firewalls have been rebooted after the problem arose; they operated fine for a day and then we started being unable to commit changes (as you can imagine when migrating a large ruleset from an old firewall there's a few changes to be made!).&lt;/LI&gt;&lt;LI&gt;No users authenticating (or being identified) as yet. There's no real traffic passing through, although we've done some "bench tests" - before adding in the AD details!&lt;/LI&gt;&lt;LI&gt;And lastly for now :-&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;msm@Hula(active)&amp;gt; show system info &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname: Hula&lt;/P&gt;&lt;P&gt;ip-address: 10.14.4.64&lt;/P&gt;&lt;P&gt;netmask: 255.255.254.0&lt;/P&gt;&lt;P&gt;default-gateway: 10.14.5.254&lt;/P&gt;&lt;P&gt;ipv6-address: unknown&lt;/P&gt;&lt;P&gt;ipv6-link-local-address: fe80::290:bff:fe37:dd0c/64&lt;/P&gt;&lt;P&gt;ipv6-default-gateway: &lt;/P&gt;&lt;P&gt;mac-address: 00:90:0b:37:dd:0c&lt;/P&gt;&lt;P&gt;time: Sun Jan 11 20:19:24 2015&lt;/P&gt;&lt;P&gt;uptime: 2 days, 13:34:16&lt;/P&gt;&lt;P&gt;family: 5000&lt;/P&gt;&lt;P&gt;model: PA-5060&lt;/P&gt;&lt;P&gt;serial: 001901000769&lt;/P&gt;&lt;P&gt;sw-version: 6.0.7&lt;/P&gt;&lt;P&gt;global-protect-client-package-version: 0.0.0&lt;/P&gt;&lt;P&gt;app-version: 480-2519&lt;/P&gt;&lt;P&gt;app-release-date: 2015/01/06&amp;nbsp; 14:56:48&lt;/P&gt;&lt;P&gt;av-version: 1459-1932&lt;/P&gt;&lt;P&gt;av-release-date: 2015/01/08&amp;nbsp; 04:00:01&lt;/P&gt;&lt;P&gt;threat-version: 480-2519&lt;/P&gt;&lt;P&gt;threat-release-date: 2015/01/06&amp;nbsp; 14:56:48&lt;/P&gt;&lt;P&gt;wildfire-version: 0&lt;/P&gt;&lt;P&gt;wildfire-release-date: unknown&lt;/P&gt;&lt;P&gt;url-filtering-version: 0000.00.00.000&lt;/P&gt;&lt;P&gt;global-protect-datafile-version: 0&lt;/P&gt;&lt;P&gt;global-protect-datafile-release-date: unknown&lt;/P&gt;&lt;P&gt;logdb-version: 6.0.6&lt;/P&gt;&lt;P&gt;platform-family: 5000&lt;/P&gt;&lt;P&gt;logger_mode: False&lt;/P&gt;&lt;P&gt;vpn-disable-mode: off&lt;/P&gt;&lt;P&gt;operational-mode: normal&lt;/P&gt;&lt;P&gt;multi-vsys: off&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Jan 2015 20:27:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6908#M5091</guid>
      <dc:creator>MikeMeredith</dc:creator>
      <dc:date>2015-01-11T20:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Frequent Running Of AddrObjRefresh Blocking Commits?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6909#M5092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;MikeMeredith,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you need the firewall to pull all groups from the AD, or could we get granular&amp;nbsp; and only have it pull a set of specific ones? That should keep the useridd process cpu/mem usage down. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That has to be the issue then... useridd is running above its means, so we need to optimize it I suppose. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't forget to mark any answers here as 'correct' or 'helpful'. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Jan 2015 20:43:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6909#M5092</guid>
      <dc:creator>mmmccorkle</dc:creator>
      <dc:date>2015-01-11T20:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: Frequent Running Of AddrObjRefresh Blocking Commits?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6910#M5093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you use FQDN Objects or dynamic Objects?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you see if you use the following CLI command "request system fqdn show"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could try to stop the last commit and then commit your configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;show jobs all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-remember the job id for the AddrObjRefresh commit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;delete job id &amp;lt;id you want to delete&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;commit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2015 09:00:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/frequent-running-of-addrobjrefresh-blocking-commits/m-p/6910#M5093</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2015-01-12T09:00:33Z</dc:date>
    </item>
  </channel>
</rss>

