<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High Data Plane CPU because of DDOS or overutilization in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-high-data-plane-cpu-because-of-ddos-or/m-p/406666#M92139</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I have seen High DP utilization due to SSL decryption, Excess amount &amp;nbsp;of traffic and also DDos.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Fri, 14 May 2021 00:20:43 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2021-05-14T00:20:43Z</dc:date>
    <item>
      <title>Knowledge sharing: High Data Plane CPU because of DDOS or overutilization (access to Palo Alto Auto Assistant may help)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-high-data-plane-cpu-because-of-ddos-or/m-p/405772#M92038</link>
      <description>&lt;P&gt;I have seen for example on a small firewall when the customer enables SSL decryption that the counters for work groups "ecdhe_key_gen", "flow_host " etc. jump. This may show that the firewall can't handle the ssl decryption or that there is an SSL DDOS attack:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmV2CAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmV2CAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXwCAK" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXwCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you have access to the Palo Alto Auto Assistant tool (like F5 ihealth but for some reason Palo Alto gives access to this tool only to Partners) you can use it to better view such issue from the Tech support file. Otherwise use the logs and global counters in the articles I provided.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For more about Palo Alto logs and their meaning you can view:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-general-logs-and-log-files-that-are/m-p/410110#M92552" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-general-logs-and-log-files-that-are/m-p/410110#M92552&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 19:41:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-high-data-plane-cpu-because-of-ddos-or/m-p/405772#M92038</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-06-14T19:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: High Data Plane CPU because of DDOS or overutilization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-high-data-plane-cpu-because-of-ddos-or/m-p/406498#M92113</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a PA-220 and decrypt all of my traffic (minus 3 protected URL categories) and I do not notice slowdowns.&amp;nbsp; I will acknowledge that I do see CPU spike, but I can confirm that I am not over-utilizing my FW.&amp;nbsp; The smaller FWs do not have a network processor; everything is emulated in software, so there will be global counters that may be a misnomer or can be ignored.&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2021 00:22:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-high-data-plane-cpu-because-of-ddos-or/m-p/406498#M92113</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-05-13T00:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: High Data Plane CPU because of DDOS or overutilization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-high-data-plane-cpu-because-of-ddos-or/m-p/406542#M92117</link>
      <description>&lt;P&gt;Yes but there is a limit to everything even to Palo Alto, which otherwise is a great firewall that is not just a server like the most other firewalls but a purpose build firewall for blocking advanced attacks. The example I talk about is that the customer firewall that was a small model I think 220 crashed and we used the Palo Alto Auto Assistant and a firewall tech support to see that the data plane delta of the max counters changed right before the crash (jumped like crazy) and it was related to SSL key generation and the number of hosts. The client mentioned that they rerouted a lot of client traffic to the firewall right before the crash it seems to have been too much for this model, so I am mentioning this to who sees similar issues about what can be checked if a higher model firewall is needed or if a Layer 7 DDOS has happened.&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2021 14:52:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-high-data-plane-cpu-because-of-ddos-or/m-p/406542#M92117</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-05-13T14:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: High Data Plane CPU because of DDOS or overutilization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-high-data-plane-cpu-because-of-ddos-or/m-p/406666#M92139</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I have seen High DP utilization due to SSL decryption, Excess amount &amp;nbsp;of traffic and also DDos.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 00:20:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-high-data-plane-cpu-because-of-ddos-or/m-p/406666#M92139</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2021-05-14T00:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: High Data Plane CPU because of DDOS or overutilization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-high-data-plane-cpu-because-of-ddos-or/m-p/406750#M92153</link>
      <description>&lt;P&gt;Yes and if the issue is still present then the Chrome tool Pan(w)achrome can also be used that is free and accessible by everyone&amp;nbsp; not like the web tool Palo Alto Auto Assistant. There is also another web tool I think named PANS that can also view logs in a tech support file but it is primary for investigating issues with the control plane issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/get-more-gui-functionality-using-pan-w-achrome/ba-p/178071" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/blogs/get-more-gui-functionality-using-pan-w-achrome/ba-p/178071&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 12:34:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-high-data-plane-cpu-because-of-ddos-or/m-p/406750#M92153</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2021-05-14T12:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Knowledge sharing: High Data Plane CPU because of DDOS or overutilization (access to Palo Alto Auto Assistant may help)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-high-data-plane-cpu-because-of-ddos-or/m-p/415625#M93279</link>
      <description>&lt;P&gt;Another info is if the client has rebooted the firewall or if the firewall crashed the max counters will all jump when the firewall sees traffic and this is normal as the counters were reseted, so don't get confused.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 14:55:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-high-data-plane-cpu-because-of-ddos-or/m-p/415625#M93279</guid>
      <dc:creator>NikolayDimitrov</dc:creator>
      <dc:date>2021-06-28T14:55:57Z</dc:date>
    </item>
  </channel>
</rss>

