Decryption problem with 5.0.7

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Decryption problem with 5.0.7

L4 Transporter

Hi,

since we've upgraded our PAs (200, 2000), we notice more and more decryption problems with HTTPS websites. The problem appears suddenly, almost all HTTPS doesn't work and a restart of the PA is required to solve the problem...And then, after one or more days it appears again...

We decided to downgrade our PAs back to 5.0.6...

Did someone also notice it?

4 REPLIES 4

L6 Presenter

Hi Hithead,

There is one reported issue with SSL decryption in 5.0.7, that might be fixed in 5.0.8.

At this point I can not get more troubleshooting to match exact symptoms because PAN-OS is already downgraded.

As of now I will suggest to be on 5.0.6.

Regards,

Hardik Shah

Please run the following commands and show the entire output on 5.0.7. The sample output would be something like below and more.

admin@500> debug dataplane pool statistics

Verify Software pools are not depleted:

Software Pools

[ 0] software packet buffer 0  : 16384/16384    0x8000000021800680

[ 1] software packet buffer 1  : 8192/8192     0x8000000022010700

[ 2] software packet buffer 2  : 8192/8192     0x8000000022818780

[ 3] software packet buffer 3  : 4096/4096     0x8000000023820800

When the issue is happening If by any chance the number is reaching to 1 that would indicate that some buffer is leaking. If this is the case you will need to open a case with Tech support to further investigate the issue.

Thanks.

Hi Shasnain,

Current PAN-OS 5.0.6 is in use, SSL Decryption may not encounter same issue which we are thinking about.

Regards,

Hardik Shah

L4 Transporter

Hi guys,

thank you for the information.

shasnain Already downgraded all my PAs to 5.0.6. So your command wouldn't help. We don't like to update it again. Thanks anyway.

A ticket has been open...Will wait for 5.0.8...

  • 3185 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!