- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-18-2021 07:34 AM
Hello everyone,
Currently, I have 2 FW model 5220 active/active version 9.0.12.
When I have Wildifire activated I have seen that I have session losses and incomplete sessions.
Can anyone help me? I have not seen any known BUGs
Regards.
05-18-2021 11:59 AM - edited 05-18-2021 12:02 PM
Can you expand on what you are actually seeing? When you're looking at these sessions do they have an associated wildfire subtype threat log associated with the traffic?
If WildFire is closing sessions, while it can be a false positive, it's generally an indication of an actual issue that should be investigated. If you go into the detailed session logs you'll see all the associated logs, otherwise you can search your Threat logs with (subtype eq wildfire-virus).
05-18-2021 11:25 PM
But the traffic that is discarded in the sessions is also ICMP and trust zone traffic.
I have done a test inside the internal network and when I leave a time ping and activate Wildfire, I see the packets are lost and sessions end.
05-20-2021 06:21 AM
You aren't seeing any other resource contention across this system when you activate Wildfire in your security profile are you? There's really not much additional overhead when assigning a wildfire profile and I've never seen it cause any packet loss or session issues by itself. There's also nothing that I'm seeing in 9.0.13 related to this type of issue.
I'd reach out to TAC and open a case on this if it's repeatable so that they can look at the system as a whole. I'm just guessing, but from my experience just enabling Wildfire wouldn't cause this sort of issue.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!