- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-06-2023 05:55 AM
Hi,
We have 3250 PA deployed in office, but we have interesting issue with traffic related to proxy particularly ZScaler/Internet access traffic (8080), we notice derogation or slowness in our access. We check the speed behind the router everything is OK, but the speed behind the PA is very slow. We have reviewed the CPU load and session for the past 10 weeks and we are consistent below average 25% CPU and below 4% average session. Check also the interface of all interfaces include the PA and Access switches no issue, BTW we have SNMP server monitoring network and all related to connection is pretty normal.
But I have notice one factor in ingress-backlogs: this session always present 24hrs.
Can someone help me to understand is this normal? or does it contribute to our issue?
I have not tried killing or ending the session yet, I want to get other opinion first.
USAGE - ATOMIC: 89.453125% TOTAL: 94.04296875%
TOP SESSIONS:
SESS-ID PCT GRP-ID COUNT Special Notes
609463 89% flow_fastpath 883
flow_forwarding 33
SESSION DETAILS
SESS-ID PROTO SZONE SRC SPORT DST DPORT IGR-IF EGR-IF TYPE APP
609463 6 Core_Zone 10.62.x.x 59980 10.77.x.x 445 ae2.309 ae2.41 FLOW ms-ds-smbv3
09-07-2023 01:52 AM
Is all of your internet traffic being routed through zsaler? If so, how is a connection established, is it a single ipsec tunnel or is each client connecting independently. Is ssl decryption being applied
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!