Lost sessions with Wildfire active

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Lost sessions with Wildfire active

L4 Transporter

Hello everyone,

Currently, I have 2 FW model 5220 active/active version 9.0.12.

When I have Wildifire activated I have seen that I have session losses and incomplete sessions.

Can anyone help me? I have not seen any known BUGs

Regards.

3 REPLIES 3

Cyber Elite
Cyber Elite

@BigPalo,

Can you expand on what you are actually seeing? When you're looking at these sessions do they have an associated wildfire subtype threat log associated with the traffic?

If WildFire is closing sessions, while it can be a false positive, it's generally an indication of an actual issue that should be investigated. If you go into the detailed session logs you'll see all the associated logs, otherwise you can search your Threat logs with (subtype eq wildfire-virus). 

But the traffic that is discarded in the sessions is also ICMP and trust zone traffic.

I have done a test inside the internal network and when I leave a time ping and activate Wildfire, I see the packets are lost and sessions end.

Cyber Elite
Cyber Elite

@BigPalo,

You aren't seeing any other resource contention across this system when you activate Wildfire in your security profile are you? There's really not much additional overhead when assigning a wildfire profile and I've never seen it cause any packet loss or session issues by itself. There's also nothing that I'm seeing in 9.0.13 related to this type of issue.

I'd reach out to TAC and open a case on this if it's repeatable so that they can look at the system as a whole. I'm just guessing, but from my experience just enabling Wildfire wouldn't cause this sort of issue. 

  • 2003 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!