Multiple PA-200 Firewall's lock up and require a reboot in order to function.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Multiple PA-200 Firewall's lock up and require a reboot in order to function.

L1 Bithead

I have 24 PA-200 firewalls.  They are running on PanOS 6.1.3.  At random times the firewall will lock up and requires the device to be power cycled to restore connectivity.  I have called Palo Alto support and them connect to one of the devices that had stopped forwarding traffic.  This specific firewall I was able to connect to the outside management interface, but this is not the case all the time.  Support told me the QOS queue was full and it was causing the issue.  I disable qos on all my firewalls and this issue still happens.  All these firewalls are connect to cable modems.  This has been happening for awhile now and is completely random.  I am wondering if anyone else is experinencing this?

4 REPLIES 4

L1 Bithead

What ISP and why kind of Cable modem? It would seem odd that it would fill the Q's up on that.  Also what you running behind your pa-200? if your doing full threat and decrypt on it, maybe your over taking your data plane?  On your dash board under system recourses what does your session count say? 

Not sure if you have thought about upgrading the Pan on it, but we are running a number of PA devices in the 7 train and love it. No issues so far. 

If your QoS was still enabled did QoS profile include class 4?

Class 4 has to be added to profile as it is default class. Even when no policy classifies traffic to class 4.

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Hi. Do you still have case open with Palo? I would go back to them and ask for another remote session to investigate a RCA. 

The case is closed, I might be able to re-open it.  The problem is, it is random, so I have to call when it happens and then I have to hope I am able to connect to the PA on the ouside management interface ip.  Would you like me to see if I can re-open it? We are using Charter cable for the ISP, the devices behind the firewall are cisco 3560 and 2960 switches.

  • 2956 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!