- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-14-2022 06:15 AM - edited 04-14-2022 06:19 AM
Having issues with palo alto pa-820. Some times when users try to load sites they just don't load. Wait some time and site usually loads. Some times it is fine, loads fast, users not getting any errors. No changes made to cause issue. Thinking it is something with dynamic updates? This started on the morning of 12-04-2022.
04-14-2022 07:35 AM
You need to monitor the traffic when it works, and when it doesn't in the firewall. You also want to do trace routes in both scenarios. See if for some reason it is falling down to a deny all. Also, not the protocol being used. I see the most issues when sites try to use quic.
04-14-2022 07:57 AM - edited 04-14-2022 08:03 AM
Looking at -Logs -Traffic and my IP and not seeing any deny under Action.
Found this what does "resources-unavailable" under "session end reason" mean?
Management CPU seems to be at 100% all the time.
04-14-2022 08:18 AM
I think you just answered your own question there. Are you doing ssl decryption? Deep packet inspection?? Those are resource hogs.
04-14-2022 08:30 AM
Where do I turn off ssl decryption? can't get to kb article.
04-14-2022 08:41 AM
IF you are running it, it would be under objects->decryption pofiles. to see what's being used. Then check to see if you have anything under profiles->decryption.
04-14-2022 08:45 AM
Just simple things first, have you tried restarting since you noticed the issue to rule out a stuck process or other software issue? That would be the first thing I do if you suddenly start noticing a new introduced issue.
Rather than disabling decryption policies, I would highly recommend you start looking at traffic to see what's changed in the past two days to push your device past it's limits. Is their additional network traffic that isn't expected? Do you have a machine spawning a lot of sessions due to something being introduced on the machine? Don't diminish security of your environment without going through root cause to figure out why your device is being overloaded if it just suddenly changed.
04-14-2022 12:17 PM
Good point. Should have asked for more information.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!