Number of session

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Number of session

L4 Transporter

Hi,

Palo alto suddenly stops client going internet .

resolving dns stops  ( dns forwarder  just giving timeout instead of  the dns query result ) .

Does it mean maximum  number of session has saturated? 

How can we know maximum number of session reached .

Where do we begin to troubleshoot 

 

Thanks

5 REPLIES 5

L6 Presenter

Hello,

 

Don't think you have reached the max number of sessions. You can check current session count on the Dashboard>System Resources:

 

sess.PNG

 

Who is the DNS server for the client? Do you have PA configured as DNS Proxy fro the clients? What can you see in the traffic logs on the PA? Can you post screen shot f the logs

 

Thx,

Myky

Cyber Elite
Cyber Elite
Your description is rather vague, has traffic stopped for all clients or just one
Can you ping upstream hosts (ISP router, 4.2.2.2,... ) From the firewall dataplane interfaces (ping source <DP IP> destination <IP>)
Is your DNS getting resolved, are any of your sessions getting rejected (show session all filter source <client IP>)
Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hi,

Can you ping upstream hosts (ISP router, 4.2.2.2,... ) From the firewall dataplane interfaces (ping source <DP IP> destination <IP>)

pa in vwire mode ,.So how can i Choose  source ip from the PA's dataplane to ping destination

 

Thanks

You can't in that case.

 

What do logs say? Does traffic stop just for 1 client or more? Check reachabilty of gateway from that client. Check reachibilty of DNS server. Check some internet address by IP. Etc.

 

 

Community Team Member

Hi @sib,

 

As already mentioned you can't specify datapane source IP to perform a ping test in vwire mode.

 

Other questions remain : 

Is your DNS getting resolved when you test it from your client ?

Are any of your sessions getting rejected :

 

> show session all filter source <client IP>

 

Also, to get more information on session numbers try the following command in the CLI :

 

> show session info

 

Cheers !

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 2168 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!