<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lost sessions with Wildfire active in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/lost-sessions-with-wildfire-active/m-p/408094#M92304</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You aren't seeing any other resource contention across this system when you activate Wildfire in your security profile are you? There's really not much additional overhead when assigning a wildfire profile and I've never seen it cause any packet loss or session issues by itself. There's also nothing that I'm seeing in 9.0.13 related to this type of issue.&lt;/P&gt;
&lt;P&gt;I'd reach out to TAC and open a case on this if it's repeatable so that they can look at the system as a whole. I'm just guessing, but from my experience just enabling Wildfire wouldn't cause this sort of issue.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 May 2021 13:21:07 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-05-20T13:21:07Z</dc:date>
    <item>
      <title>Lost sessions with Wildfire active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lost-sessions-with-wildfire-active/m-p/407532#M92243</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;Currently, I have 2 FW model 5220 active/active version 9.0.12.&lt;/P&gt;&lt;P&gt;When I have Wildifire activated I have seen that I have session losses and incomplete sessions.&lt;/P&gt;&lt;P&gt;Can anyone help me? I have not seen any known BUGs&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 14:34:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lost-sessions-with-wildfire-active/m-p/407532#M92243</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2021-05-18T14:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Lost sessions with Wildfire active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lost-sessions-with-wildfire-active/m-p/407628#M92246</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Can you expand on what you are actually seeing? When you're looking at these sessions do they have an associated wildfire subtype threat log associated with the traffic?&lt;/P&gt;
&lt;P&gt;If WildFire is closing sessions, while it can be a false positive, it's generally an indication of an actual issue that should be investigated. If you go into the detailed session logs you'll see all the associated logs, otherwise you can search your Threat logs with (subtype eq wildfire-virus).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 19:02:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lost-sessions-with-wildfire-active/m-p/407628#M92246</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-05-18T19:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Lost sessions with Wildfire active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lost-sessions-with-wildfire-active/m-p/407704#M92251</link>
      <description>&lt;P&gt;But the traffic that is discarded in the sessions is also ICMP and trust zone traffic.&lt;/P&gt;&lt;P&gt;I have done a test inside the internal network and when I leave a time ping and activate Wildfire, I see the packets are lost and sessions end.&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 06:25:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lost-sessions-with-wildfire-active/m-p/407704#M92251</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2021-05-19T06:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: Lost sessions with Wildfire active</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/lost-sessions-with-wildfire-active/m-p/408094#M92304</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You aren't seeing any other resource contention across this system when you activate Wildfire in your security profile are you? There's really not much additional overhead when assigning a wildfire profile and I've never seen it cause any packet loss or session issues by itself. There's also nothing that I'm seeing in 9.0.13 related to this type of issue.&lt;/P&gt;
&lt;P&gt;I'd reach out to TAC and open a case on this if it's repeatable so that they can look at the system as a whole. I'm just guessing, but from my experience just enabling Wildfire wouldn't cause this sort of issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 13:21:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/lost-sessions-with-wildfire-active/m-p/408094#M92304</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-05-20T13:21:07Z</dc:date>
    </item>
  </channel>
</rss>

