- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-24-2018 01:28 PM
Hi,
we are experiencing this issue that we are troubleshooting from a couple of days. we have done all our checks WAN and LAN side however there is a paloalto firewall between WAN routers and core switch in a Vwire mode with an any-any rule. the only problem I have noticed so far is that at the time of issue the firewall is not too responsive i.e. the gui takes ages but cpu shoes minimum usage.
another thing I noticed was incrementing logical interface dropped packets:
show interface ethernet1/4
Logical interface counters read from CPU:
--------------------------------------------------------------------------------
bytes received 79386995797798
bytes transmitted 67887362097627
packets received 2533039042
packets transmitted 3904754824
receive errors 0
packets dropped 29286415
packets dropped by flow state check 63657
I can see them on all active interfaces.
anyone has any idea of how I go by troubleshooting this further as I am very new PAs.
Thanks in advance.
Regards,
Ali
09-24-2018 02:03 PM
Hello,
In the GUI, make sure the policy is set to log at session end. Then check the monitor tab for the traffic and see what is getting blocked.
Regards,
09-24-2018 02:12 PM
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!