- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-15-2022 04:49 AM
Dear all !!
Facing a big issue after upgraded to 9.1.14. Lots of Discards in legitimate traffic
show session id 6088287
Session 6088287
c2s flow:
source: 172.27.107.40 [Aulas_Int]
dst: 138.68.127.222
proto: 6
sport: 59736 dport: 443
state: DISCARD type: FLOW
src user: unknown
dst user: unknown
offload: Yes
s2c flow:
source: 138.68.127.222 [vCMP_AULAS]
dst: 172.27.107.40
proto: 6
sport: 443 dport: 59736
state: DISCARD type: FLOW
src user: unknown
dst user: unknown
qos node: ae1.115, qos member N/A Qid 0
offload: Yes
Slot : 1
DP : 0
index(local): : 6088287
start time : Mon Jun 6 08:23:37 2022
timeout : 90 sec
time to live : 54 sec
total byte count(c2s) : 1435
total byte count(s2c) : 20924
layer7 packet count(c2s) : 13
layer7 packet count(s2c) : 18
vsys : vsys1
application : ssl
rule : Cat_Educacion
service timeout override(index) : False
session to be logged at end : True
session in session ager : True
session updated by HA peer : False
layer7 processing : enabled
URL filtering enabled : True
URL category : educational-institutions, low-risk
session via syn-cookies : False
session terminated on host : False
session traverses tunnel : False
session terminate tunnel : False
captive portal session : False
ingress interface : ae1.115
egress interface : ae2.130
session QoS rule : N/A (class 4)
tracker stage l7proc : ctd tcp deny
end-reason : unknown
Do you have any idea what can be the issue of so many Discards?, that's really driving me crazy
Thank you in advance for your help!
Lukgom
06-15-2022 12:19 PM
Hello,
I had issues with that code as well, had to go back to 9.1.11 :(.
Regards,
06-15-2022 05:34 PM
We have a couple of customers who are hitting PAN-194395. Are you decrypting traffic?
FYI:
06-15-2022 10:44 PM
Hello
It seems like an issue within this version
Thanks
Lukgom
06-15-2022 10:59 PM - edited 06-15-2022 11:24 PM
Hi @emr_1
Thanks for your answer
We are decrypting traffic in some categories only.
Just did what you told me to, enabling Strip ALPN in decryption profile and use that one in the decryption police, but no luck
The only workaround working for us is an application override to that destination-website
Lukgom
06-16-2022 06:26 AM
Hi
The issue just resolved itself by going to the passive node. I will have to reboot the issued one
Thank you all for your help
Lukgom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!