<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Several sessions outage/interface drops in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/several-sessions-outage-interface-drops/m-p/167651#M53518</link>
    <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had a TAC case opened&amp;nbsp;some time ago to get clarification for the "&lt;SPAN&gt;receive error" counters&lt;/SPAN&gt; and below the feedback:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------------------------------------------- &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;I would like to share with you my findings from the log analysis. The receive error are logical errors although they are shown under Hardware interface errors. The possible events and packets could be the following incorrect length of VLAN tag, unexpected VLAN tag, unsupported L2 protocol, incorrect IP checksum, TCP/UDP packet checksum error, TCP/UDP port 0, Invalid TCP flag, etc. The following document has more details and explains how exactly this counters are working :&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/The-Difference-Between-Receive-Errors-for-Hardware-and-Logical/ta-p/59039" target="_self"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/The-Difference-Between-Receive-Errors-for-Hardware-and-Logical/ta-p/59039&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;From my investigation I found that there is a high number of STP packets received which are not supported on the FW, dot1q tag errors, L4 checksum errors ( packets with TCP/UDP checksum not correct ). I attached the screenshots of our analysing tools in the file section of the case where you can check the high load with this type of traffic. In addition, the counter is accumulated since the last reboot of the device and therefore is the large number of errors. I hope this explanation will give you more details how exactly the counters are presented and what is the usual type of traffic triggering the counter to increase. If you have any additional questions in meantime, please feel free to contact us.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't&amp;nbsp;know if it is applicable to the&amp;nbsp;ae interface (l think it should) but below the command that will get more inform:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;amians@pxxxx(active)&amp;gt; show counter global filter severity drop&lt;/P&gt;&lt;P&gt;Global counters:&lt;BR /&gt;Elapsed time since last sampling: 1.248 seconds&lt;/P&gt;&lt;P&gt;name value rate severity category aspect description&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;session_state_error 114323 0 drop session pktproc Session state error&lt;BR /&gt;session_dup_pkt_drop 16336698 20 drop session resource Duplicate packet: Applies only for multi-DP platform with hardware (Tiger) broadcasting pkt to all DPs&lt;BR /&gt;flow_rcv_err 16752983 24 drop flow parse Packets dropped: flow stage receive error&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;flow_rcv_dot1q_tag_err&lt;/FONT&gt; 26564200 16 drop flow parse Packets dropped: 802.1q tag not configured&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jul 2017 08:36:46 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-07-21T08:36:46Z</dc:date>
    <item>
      <title>Several sessions outage/interface drops</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-sessions-outage-interface-drops/m-p/167465#M53476</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a PA-5050 with PaNoS 7.0.7, we are expecting that there are moments during the day when the traffic increases that there is a outage for several sessions, but the sessions are still very low for this PA-5050. And we dont know why some sessions are not being established.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would like to discard if this is caused for PA. Looking the PA interface. We have an ae with 4 ports.&amp;nbsp;We see packet drops in this ae1, the packets dropped are incresing all the time.&lt;/P&gt;&lt;P&gt;On the another hand, if we check all the interfaces (&lt;SPAN&gt;ethernet1/21 ethernet1/22 ethernet1/23 ethernet1/24)&lt;/SPAN&gt; bonding in this ae, we dont see any errors. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show interface ae1&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Name: ae1, ID: 48&lt;BR /&gt;Link status:&lt;BR /&gt;Runtime link speed/duplex/state: [n/a]/[n/a]/up&lt;BR /&gt;Configured link speed/duplex/state: auto/auto/auto&lt;BR /&gt;MAC address:&lt;BR /&gt;Port MAC address 00&lt;BR /&gt;Aggregate group members: 4&lt;BR /&gt;ethernet1/21 ethernet1/22 ethernet1/23 ethernet1/24&lt;BR /&gt;Operation mode: layer3&lt;BR /&gt;Untagged sub-interface support: no&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Name: ae1, ID: 48&lt;BR /&gt;Operation mode: layer3&lt;BR /&gt;Interface management profile: N/A&lt;BR /&gt;Service configured: LACP&lt;BR /&gt;Zone: N/A, virtual system: vsys1&lt;BR /&gt;Adjust TCP MSS: no&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Hardware interface counters read from CPU:&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;bytes received 817930387942&lt;BR /&gt;bytes transmitted 796893216522&lt;BR /&gt;packets received 1797090261&lt;BR /&gt;packets transmitted 1569474090&lt;BR /&gt;receive incoming errors 0&lt;BR /&gt;receive discarded 0&lt;BR /&gt;receive errors 64162355&lt;BR /&gt;packets dropped 0&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Logical interface counters read from CPU:&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;bytes received 20819118&lt;BR /&gt;bytes transmitted 6130932&lt;BR /&gt;packets received 98682&lt;BR /&gt;packets transmitted 49443&lt;BR /&gt;receive errors 0&lt;BR /&gt;&lt;STRONG&gt;packets dropped 49325&lt;/STRONG&gt;&lt;BR /&gt;packets dropped by flow state check 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show interface ethernet1/21&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Name: ethernet1/21, ID: 36&lt;BR /&gt;Link status:&lt;BR /&gt;Runtime link speed/duplex/state: 10000/full/up&lt;BR /&gt;Configured link speed/duplex/state: auto/auto/auto&lt;BR /&gt;MAC address:&lt;BR /&gt;Port MAC address 00:1&lt;BR /&gt;Aggregate group : ae1&lt;BR /&gt;Operation mode: layer3&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;Physical port counters read from MAC:&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;rx-broadcast 2382266&lt;BR /&gt;rx-bytes 2428164611097&lt;BR /&gt;rx-multicast 1316048&lt;BR /&gt;rx-unicast 2213305474&lt;BR /&gt;tx-broadcast 1849&lt;BR /&gt;tx-bytes 1736956163089&lt;BR /&gt;tx-multicast 12326&lt;BR /&gt;tx-unicast 1653417852&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Hardware interface counters read from CPU:&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;bytes received 0&lt;BR /&gt;bytes transmitted 0&lt;BR /&gt;packets received 0&lt;BR /&gt;packets transmitted 0&lt;BR /&gt;receive incoming errors 0&lt;BR /&gt;receive discarded 1&lt;BR /&gt;receive errors 0&lt;BR /&gt;&lt;STRONG&gt;packets dropped 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why we can see these errores in ae interface?? why these erros are not shoed in ethernet interface in this ae???&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 14:10:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-sessions-outage-interface-drops/m-p/167465#M53476</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2017-07-20T14:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Several sessions outage/interface drops</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-sessions-outage-interface-drops/m-p/167526#M53495</link>
      <description>&lt;P&gt;When you create an aggregate ethernet, the counters move up from the physical interface to the logical one. The dropped packet counter normally almost always increases, unless you have an any-any-allow policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the counter which you should be worried about is the receive error counter. Examples which result in such errors are broken cables, interfaces or transievers&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 18:49:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-sessions-outage-interface-drops/m-p/167526#M53495</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2017-07-20T18:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: Several sessions outage/interface drops</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-sessions-outage-interface-drops/m-p/167535#M53497</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9102"&gt;@soporteseguridad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;already pointed out that you're actually looking at the wrong 'bad' figure in what you have listed. Are these SFP interfaces? I've seen interfaces have recieve issues showing on the PA side of things simply because of a dirty ferule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;More importantly your&amp;nbsp;&lt;SPAN&gt;receive errors is what is alarming with the stats that you have posted and are far more likely to be your issue here. What type of switch do you have on the other end, do you see the same errors if you look on that end of the link?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 19:09:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-sessions-outage-interface-drops/m-p/167535#M53497</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-20T19:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Several sessions outage/interface drops</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/several-sessions-outage-interface-drops/m-p/167651#M53518</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had a TAC case opened&amp;nbsp;some time ago to get clarification for the "&lt;SPAN&gt;receive error" counters&lt;/SPAN&gt; and below the feedback:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------------------------------------------- &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;I would like to share with you my findings from the log analysis. The receive error are logical errors although they are shown under Hardware interface errors. The possible events and packets could be the following incorrect length of VLAN tag, unexpected VLAN tag, unsupported L2 protocol, incorrect IP checksum, TCP/UDP packet checksum error, TCP/UDP port 0, Invalid TCP flag, etc. The following document has more details and explains how exactly this counters are working :&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/The-Difference-Between-Receive-Errors-for-Hardware-and-Logical/ta-p/59039" target="_self"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/The-Difference-Between-Receive-Errors-for-Hardware-and-Logical/ta-p/59039&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;From my investigation I found that there is a high number of STP packets received which are not supported on the FW, dot1q tag errors, L4 checksum errors ( packets with TCP/UDP checksum not correct ). I attached the screenshots of our analysing tools in the file section of the case where you can check the high load with this type of traffic. In addition, the counter is accumulated since the last reboot of the device and therefore is the large number of errors. I hope this explanation will give you more details how exactly the counters are presented and what is the usual type of traffic triggering the counter to increase. If you have any additional questions in meantime, please feel free to contact us.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't&amp;nbsp;know if it is applicable to the&amp;nbsp;ae interface (l think it should) but below the command that will get more inform:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;amians@pxxxx(active)&amp;gt; show counter global filter severity drop&lt;/P&gt;&lt;P&gt;Global counters:&lt;BR /&gt;Elapsed time since last sampling: 1.248 seconds&lt;/P&gt;&lt;P&gt;name value rate severity category aspect description&lt;BR /&gt;--------------------------------------------------------------------------------&lt;BR /&gt;session_state_error 114323 0 drop session pktproc Session state error&lt;BR /&gt;session_dup_pkt_drop 16336698 20 drop session resource Duplicate packet: Applies only for multi-DP platform with hardware (Tiger) broadcasting pkt to all DPs&lt;BR /&gt;flow_rcv_err 16752983 24 drop flow parse Packets dropped: flow stage receive error&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;flow_rcv_dot1q_tag_err&lt;/FONT&gt; 26564200 16 drop flow parse Packets dropped: 802.1q tag not configured&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2017 08:36:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/several-sessions-outage-interface-drops/m-p/167651#M53518</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-21T08:36:46Z</dc:date>
    </item>
  </channel>
</rss>

