<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rule Counters on HA Pair With Transfered Sessions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rule-counters-on-ha-pair-with-transfered-sessions/m-p/205808#M60408</link>
    <description>&lt;P&gt;Let us say you have a firewall pair configured and rules configured and one day you fail them over - or they fail over. The primary is rebooted. When the primary comes back up all sessions are transferred back and everything is fine. Except, as I understand it, the only time rule counters are reset is after a reboot (or the backplane is restarted). So if those sessions are never again dropped, and thus never hit the rule allowing them again, that rule may appear as unused.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this correct and, if so, is there a way to resovle it for a rule-base review - to know which rules are really not being used and avoid disabling "unused rules" that are really just maintaining their sessions between failovers?&lt;/P&gt;</description>
    <pubDate>Thu, 15 Mar 2018 23:57:39 GMT</pubDate>
    <dc:creator>Knobdy</dc:creator>
    <dc:date>2018-03-15T23:57:39Z</dc:date>
    <item>
      <title>Rule Counters on HA Pair With Transfered Sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-counters-on-ha-pair-with-transfered-sessions/m-p/205808#M60408</link>
      <description>&lt;P&gt;Let us say you have a firewall pair configured and rules configured and one day you fail them over - or they fail over. The primary is rebooted. When the primary comes back up all sessions are transferred back and everything is fine. Except, as I understand it, the only time rule counters are reset is after a reboot (or the backplane is restarted). So if those sessions are never again dropped, and thus never hit the rule allowing them again, that rule may appear as unused.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this correct and, if so, is there a way to resovle it for a rule-base review - to know which rules are really not being used and avoid disabling "unused rules" that are really just maintaining their sessions between failovers?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 23:57:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-counters-on-ha-pair-with-transfered-sessions/m-p/205808#M60408</guid>
      <dc:creator>Knobdy</dc:creator>
      <dc:date>2018-03-15T23:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Counters on HA Pair With Transfered Sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-counters-on-ha-pair-with-transfered-sessions/m-p/205993#M60473</link>
      <description>&lt;P&gt;What you really want is a new feature in PAN-OS 8.1, but I wouldn't recommend installing it quite yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/81/pan-os/newfeaturesguide/management-features/rule-usage-tracking" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/81/pan-os/newfeaturesguide/management-features/rule-usage-tracking&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 16:09:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-counters-on-ha-pair-with-transfered-sessions/m-p/205993#M60473</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2018-03-16T16:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Counters on HA Pair With Transfered Sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-counters-on-ha-pair-with-transfered-sessions/m-p/205994#M60474</link>
      <description>So I’m correct...that’s not good.</description>
      <pubDate>Fri, 16 Mar 2018 16:12:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-counters-on-ha-pair-with-transfered-sessions/m-p/205994#M60474</guid>
      <dc:creator>Knobdy</dc:creator>
      <dc:date>2018-03-16T16:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: Rule Counters on HA Pair With Transfered Sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rule-counters-on-ha-pair-with-transfered-sessions/m-p/205997#M60476</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85039"&gt;@Knobdy&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You are indeed correct. Once a PAN reboots, the counters are reset to 0 regardless of current sessions on the other HA unit. I agree with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7143"&gt;@mlinsemier&lt;/a&gt;, wait on 8.1 for a while till they work out some bugs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 16:17:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rule-counters-on-ha-pair-with-transfered-sessions/m-p/205997#M60476</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-16T16:17:42Z</dc:date>
    </item>
  </channel>
</rss>

