<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Packet drop counter increment normal? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/packet-drop-counter-increment-normal/m-p/165285#M53162</link>
    <description>&lt;P&gt;well the good thing is that there usually is not a lot of 'low level' packetloss, most of the time that happens when you have a faulty cable or incorrect speed/duplex setting, everything else usually happens in the processing layer where packets are either discarded due to policy (security policy, security profile, QoS, DoS protection , ....) or because the system is overloaded&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;these commands will help you pinpoint 'system overload'&lt;/P&gt;
&lt;P&gt;&amp;gt;show running resource-monitor&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when the packet descriptor (buffers) are extremely high (past 85% packetloss may occur)&lt;/P&gt;
&lt;P&gt;(don't worry too much about cpu or processes running 100%, some are pre-spun to 100%, others are perfectly ok at 100% as long as the buffers and pools are 'free')&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;&amp;gt; debug dataplane pool statistics&lt;/P&gt;
&lt;P&gt;when the software/harware memory pools run dry&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;at first glance you have a very low amount of dropped packets in the system, thats good. Please check with your ISP, usually a 'box on the wall means a regular routing/modem device that has automatic settings which will fix your bad quality voip issue when you set the firewall to comply, else try switching out the cable just to make sure&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if that doesn;t fix the issue you could also try transplanting your configuration on a different firewall interface so you can exclude a faulty hardware port also&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jul 2017 18:19:32 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2017-07-07T18:19:32Z</dc:date>
    <item>
      <title>Packet drop counter increment normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-drop-counter-increment-normal/m-p/165201#M53151</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had a Lync meeting yesterday that was reported with poor performance and dropped calls.&lt;/P&gt;&lt;P&gt;The Lync Monitor dashboard indicates dropped packets and jitter in that time frame.&lt;/P&gt;&lt;P&gt;I checked the Lync server and the LAN switch its ESXi host is connected to, no alerts or reports of packet loss.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see that&amp;nbsp;all of our&amp;nbsp;PA 3020 interfaces have a packet drop counter that is incrementing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this normal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is example of ethernet 1/1 our public facing interface, but they are all doing it, including internal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PAdrops3.jpg" style="width: 452px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10220i6A85830CC40834E8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PAdrops3.jpg" alt="PAdrops3.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I did a catch all packet capture and opened the drop.pcap file in wireshark, small sample&amp;nbsp;looks like this.&amp;nbsp; Is this normal for networks to drop these packets and increment the packet drop counter?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PAdrops2.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10219iE660D8C0DFD84E47/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PAdrops2.jpg" alt="PAdrops2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Drop-Counters-in-quot-Show-Interface-Ethernet-quot/ta-p/51978" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/Packet-Drop-Counters-in-quot-Show-Interface-Ethernet-quot/ta-p/51978&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 13:55:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-drop-counter-increment-normal/m-p/165201#M53151</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-07-07T13:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Packet drop counter increment normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-drop-counter-increment-normal/m-p/165212#M53153</link>
      <description>&lt;P&gt;this packetcpture may not capture all the dropped packets seen in the interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;a little bckground&lt;/P&gt;
&lt;P&gt;the dropped packets on the interface are usually malformed packets the interface wont accept (too large frames, broken, missing header, ...)&lt;/P&gt;
&lt;P&gt;the packets seen in the packet-diag are packets discarded by the packet processing CPU, which is after the interface.packets dropped by the processor appear in the global counters&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you'll want to run &amp;gt; show counter global filter delta yes (optionally 'packet-filter yes' if you added packet-diag filters)&lt;/P&gt;
&lt;P&gt;and see which drop counters increment there&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it looks like you set a manual link speed and duplex, did you also set this speed on the connected switch? if not, you'll want to change the firewall to auto-auto or set the switch to 100/full. a mismatch in auto/static will also cause packet drops due to negotiation mishaps&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 14:11:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-drop-counter-increment-normal/m-p/165212#M53153</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-07-07T14:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Packet drop counter increment normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-drop-counter-increment-normal/m-p/165269#M53161</link>
      <description>&lt;P&gt;Thanks reaper,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 1/1 interface is set to 100 and full.&amp;nbsp; It's other end goes to a small box on the wall representing our Internet provider.&amp;nbsp; I am assuming there must have been a requirement for it to be setup that way.&amp;nbsp; I would have to call the ISP to verify I guess.&amp;nbsp;Thanks for noticing...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran the command you reference, but do not see nearly the drop number(s) I see when running the show interface command.&amp;nbsp; Of course I am a newbie and trying to understand what is relevant.&amp;nbsp;&amp;nbsp; Still confusing on how to monitor packet loss.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PAcounters.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10228i20258AEDE3052797/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PAcounters.jpg" alt="PAcounters.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 17:58:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-drop-counter-increment-normal/m-p/165269#M53161</guid>
      <dc:creator>OMatlock</dc:creator>
      <dc:date>2017-07-07T17:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Packet drop counter increment normal?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/packet-drop-counter-increment-normal/m-p/165285#M53162</link>
      <description>&lt;P&gt;well the good thing is that there usually is not a lot of 'low level' packetloss, most of the time that happens when you have a faulty cable or incorrect speed/duplex setting, everything else usually happens in the processing layer where packets are either discarded due to policy (security policy, security profile, QoS, DoS protection , ....) or because the system is overloaded&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;these commands will help you pinpoint 'system overload'&lt;/P&gt;
&lt;P&gt;&amp;gt;show running resource-monitor&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when the packet descriptor (buffers) are extremely high (past 85% packetloss may occur)&lt;/P&gt;
&lt;P&gt;(don't worry too much about cpu or processes running 100%, some are pre-spun to 100%, others are perfectly ok at 100% as long as the buffers and pools are 'free')&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;&amp;gt; debug dataplane pool statistics&lt;/P&gt;
&lt;P&gt;when the software/harware memory pools run dry&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;at first glance you have a very low amount of dropped packets in the system, thats good. Please check with your ISP, usually a 'box on the wall means a regular routing/modem device that has automatic settings which will fix your bad quality voip issue when you set the firewall to comply, else try switching out the cable just to make sure&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if that doesn;t fix the issue you could also try transplanting your configuration on a different firewall interface so you can exclude a faulty hardware port also&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2017 18:19:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/packet-drop-counter-increment-normal/m-p/165285#M53162</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-07-07T18:19:32Z</dc:date>
    </item>
  </channel>
</rss>

