- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-17-2016 07:30 PM
Hi,
Palo alto suddenly stops client going internet .
resolving dns stops ( dns forwarder just giving timeout instead of the dns query result ) .
Does it mean maximum number of session has saturated?
How can we know maximum number of session reached .
Where do we begin to troubleshoot
Thanks
12-18-2016 07:31 AM - edited 12-18-2016 07:43 AM
Hello,
Don't think you have reached the max number of sessions. You can check current session count on the Dashboard>System Resources:
Who is the DNS server for the client? Do you have PA configured as DNS Proxy fro the clients? What can you see in the traffic logs on the PA? Can you post screen shot f the logs
Thx,
Myky
12-18-2016 01:28 PM
12-28-2016 03:28 PM
Hi,
Can you ping upstream hosts (ISP router, 4.2.2.2,... ) From the firewall dataplane interfaces (ping source <DP IP> destination <IP>)
pa in vwire mode ,.So how can i Choose source ip from the PA's dataplane to ping destination
Thanks
12-28-2016 10:53 PM
You can't in that case.
What do logs say? Does traffic stop just for 1 client or more? Check reachabilty of gateway from that client. Check reachibilty of DNS server. Check some internet address by IP. Etc.
12-29-2016 01:03 AM
Hi @sib,
As already mentioned you can't specify datapane source IP to perform a ping test in vwire mode.
Other questions remain :
Is your DNS getting resolved when you test it from your client ?
Are any of your sessions getting rejected :
> show session all filter source <client IP>
Also, to get more information on session numbers try the following command in the CLI :
> show session info
Cheers !
-Kim.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!