<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA  5220 Packet Descriptor Max value in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300483#M78508</link>
    <description>&lt;P&gt;It is always pleasure to read you posts.&lt;/P&gt;&lt;P&gt;We are running PAN OS 8.1.9.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For Company users &amp;nbsp;accessing Internet&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have INT. and EXT. zone. &amp;nbsp;on each separate &amp;nbsp;physical interface&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have one Internal Zone for our Corp Users and all Internet traffic for users flow via this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Two separate Zone for Guest Internet traffic on separate &amp;nbsp;ISP connection.&lt;/P&gt;&lt;P&gt;Top used rule is Corp Internal users accessing internet &amp;nbsp;on port 80 and 443.&lt;/P&gt;&lt;P&gt;This rule is mostly used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea how can I narrow it down if I know the mostly used rule?&lt;/P&gt;&lt;P&gt;Also is it possible to get the email when Packet descriptor runs 100%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Nov 2019 04:55:45 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2019-11-25T04:55:45Z</dc:date>
    <item>
      <title>PA  5220 Packet Descriptor Max value</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300376#M78489</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I run show running resource monitor. I see packet descriptor max value most of time above 80 like&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in 90's. sometimes 100 100.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Packet descriptor average value is still under 80.&lt;/P&gt;&lt;P&gt;We have ssl decryption enabled on the &amp;nbsp;PA.&lt;/P&gt;&lt;P&gt;Also we have decrypt mirror configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What can be reason that packet descriptor is going over 90 so often?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2019 04:05:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300376#M78489</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-23T04:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: PA  5220 Packet Descriptor Max value</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300424#M78491</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would really need to dive into your setup, logs, and possibly netflow data to determine this with any real certainty. The only thing effecting your descriptor count would be the additional buffer and descriptor allocation happening for your decrypt mirror configuration.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Nov 2019 09:18:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300424#M78491</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-11-24T09:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: PA  5220 Packet Descriptor Max value</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300440#M78494</link>
      <description>&lt;P&gt;We have netflow configured in solar.&lt;/P&gt;&lt;P&gt;When i check the decrypt mirror port it is 10gig and i see no errors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you say below&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The only thing effecting your descriptor count would be the additional buffer and descriptor allocation happening for your decrypt mirror configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For this should i configure the netflow for the decrypt mirror port?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mike&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Nov 2019 16:24:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300440#M78494</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-24T16:24:32Z</dc:date>
    </item>
    <item>
      <title>Re: PA  5220 Packet Descriptor Max value</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300441#M78495</link>
      <description>&lt;P&gt;Also let me know what next step i can take to isolate this?&lt;/P&gt;</description>
      <pubDate>Sun, 24 Nov 2019 16:27:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300441#M78495</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-24T16:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: PA  5220 Packet Descriptor Max value</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300482#M78507</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So I wouldn't get too hung up on the decrypt mirror port; I simply meant that to mean that you have increased load across your device and the additional load by configuring a decrypt mirror isn't helping things.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You'll need to try and see exactly what is causing your traffic load to spike and if its legitimate traffic that needs to be processed or something behaving poorly; it's quite possible that at times your device is simply under stress, and if you still average below 80% I wouldn't be overly concerned about it unless it starts causing issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To attempt to see what is flooding in while you notice the descriptor issue, you'll need to monitor what traffic is actually going across the device. Netflow certainly helps with that if you already have it configured, but you could also utilize the Chrome extension pan(w)achrome to see if you can spot where traffic is high to narrow down your search to a particular zone or interface so you have less information to search through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What version of PAN-OS are you actually running; there have been plenty of software issues where you can see high descriptor counts due to bugs that you may be running into.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 03:49:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300482#M78507</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-11-25T03:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: PA  5220 Packet Descriptor Max value</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300483#M78508</link>
      <description>&lt;P&gt;It is always pleasure to read you posts.&lt;/P&gt;&lt;P&gt;We are running PAN OS 8.1.9.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For Company users &amp;nbsp;accessing Internet&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have INT. and EXT. zone. &amp;nbsp;on each separate &amp;nbsp;physical interface&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have one Internal Zone for our Corp Users and all Internet traffic for users flow via this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Two separate Zone for Guest Internet traffic on separate &amp;nbsp;ISP connection.&lt;/P&gt;&lt;P&gt;Top used rule is Corp Internal users accessing internet &amp;nbsp;on port 80 and 443.&lt;/P&gt;&lt;P&gt;This rule is mostly used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea how can I narrow it down if I know the mostly used rule?&lt;/P&gt;&lt;P&gt;Also is it possible to get the email when Packet descriptor runs 100%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 04:55:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300483#M78508</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-25T04:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: PA  5220 Packet Descriptor Max value</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300716#M78559</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't believe that the descriptor hitting 100% is something you can get an email for at the moment; likewise knowing the rule doesn't really tell you anything about why your buffer and descriptor would be rising. You might want to reach out to support and see if there is any additional logging they can enable to tell you exactly what is using the available descriptors.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 03:42:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/300716#M78559</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-11-26T03:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: PA  5220 Packet Descriptor Max value</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/301672#M78701</link>
      <description>&lt;P&gt;Here is last 7 days reports of Packet Descriptor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Resource utilization (%) during last 7 days:&lt;BR /&gt;session (average):&lt;BR /&gt;1 1 2 2 2 2 2&lt;BR /&gt;session (maximum):&lt;BR /&gt;1 2 3 3 3 4 3&lt;BR /&gt;packet buffer (average):&lt;BR /&gt;1 1 1 1 1 1 1&lt;BR /&gt;packet buffer (maximum):&lt;BR /&gt;8 7 6 82 3 26 9&lt;BR /&gt;packet descriptor (average):&lt;BR /&gt;0 0 0 1 1 1 1&lt;BR /&gt;packet descriptor (maximum):&lt;BR /&gt;1 2 3 5 5 4 5&lt;BR /&gt;packet descriptor (on-chip) (average):&lt;BR /&gt;3 3 4 4 4 4 4&lt;BR /&gt;packet descriptor (on-chip) (maximum):&lt;BR /&gt;100 100 99 100 60 100 91&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will check with out SE&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2019 17:27:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/301672#M78701</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-02T17:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: PA  5220 Packet Descriptor Max value</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/301987#M78746</link>
      <description>&lt;P&gt;Opened case with PA as per them&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we should not worry about Spike of Packet descriptor to 100%.&lt;/P&gt;&lt;P&gt;Worry about DP avergage cpu it it goes over 80% for extended period of time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q: Also any reason you know what can cause the PD spike to 100%?&lt;BR /&gt;A: The high DP (Dataplane) can be cause application usage, so we need to look at traffic patterns, in your case, the past 5 hours to understand spikes to 100%.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 21:50:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-5220-packet-descriptor-max-value/m-p/301987#M78746</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-03T21:50:08Z</dc:date>
    </item>
  </channel>
</rss>

