Lots of Discards after upgrading to 9.1.14

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Lots of Discards after upgrading to 9.1.14

L0 Member

Dear all !!


Facing a big issue after upgraded to 9.1.14. Lots of Discards in legitimate traffic


show session id 6088287

Session 6088287

c2s flow:
source: [Aulas_Int]
proto: 6
sport: 59736 dport: 443
state: DISCARD type: FLOW
src user: unknown
dst user: unknown
offload: Yes


s2c flow:
source: [vCMP_AULAS]
proto: 6
sport: 443 dport: 59736
state: DISCARD type: FLOW
src user: unknown
dst user: unknown
qos node: ae1.115, qos member N/A Qid 0
offload: Yes


Slot : 1
DP : 0
index(local): : 6088287
start time : Mon Jun 6 08:23:37 2022
timeout : 90 sec
time to live : 54 sec
total byte count(c2s) : 1435
total byte count(s2c) : 20924
layer7 packet count(c2s) : 13
layer7 packet count(s2c) : 18
vsys : vsys1
application : ssl
rule : Cat_Educacion
service timeout override(index) : False
session to be logged at end : True
session in session ager : True
session updated by HA peer : False
layer7 processing : enabled
URL filtering enabled : True
URL category : educational-institutions, low-risk
session via syn-cookies : False
session terminated on host : False
session traverses tunnel : False
session terminate tunnel : False
captive portal session : False
ingress interface : ae1.115
egress interface : ae2.130
session QoS rule : N/A (class 4)
tracker stage l7proc : ctd tcp deny
end-reason : unknown


Do you have any idea what can be the issue of so many Discards?, that's really driving me crazy


Thank you in advance for your help!



Cyber Elite
Cyber Elite


I had issues with that code as well, had to go back to 9.1.11 :(.


L5 Sessionator

We have a couple of customers who are hitting PAN-194395. Are you decrypting traffic?




It seems like an issue within this version



L1 Bithead

Hi @emr_1 


Thanks for your answer
We are decrypting traffic in some categories only.

Just did what you told me to, enabling Strip ALPN in decryption profile and use that one in the decryption police, but no luck


The only workaround working for us is an application override to that destination-website





L1 Bithead



The issue just resolved itself by going to the passive node. I will have to reboot the issued one


Thank you all for your help


  • 5 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!