Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

PA-3020 Dataplane 100%

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PA-3020 Dataplane 100%

L0 Member

We have aggregated ports for the PA to "handle" what Consolidated has for us on a 2GB circuit.  Is this a case where our 3020 can't handle the traffic we have or is excessive logging a more likely culprit.  GoldSeal has our support and the need for immediate help is basically non existent.  Any suggestions on how to determine dataplane issues or get around GoldSeal for someone to read our TAC file?

3 REPLIES 3

L3 Networker

Try to generate the tech support file from the firewall web UI and verify the monitoring outputs of the data plane(DP).

and also using CLI commands > show running resources utilization 

 

>Check is there any layer-2 loop in a network by disabling the LANB side interfaces.

 

 

 

Best Regards,
Suresh

L0 Member

Looks something like this:

 

> show running resource-monitor

Resource monitoring sampling data (per second):

CPU load sampling by group:
flow_lookup : 83%
flow_fastpath : 83%
flow_slowpath : 83%
flow_forwarding : 83%
flow_mgmt : 82%
flow_ctrl : 82%
nac_result : 83%
flow_np : 83%
dfa_result : 83%
module_internal : 83%
aho_result : 83%
zip_result : 83%
pktlog_forwarding : 83%
lwm : 0%
flow_host : 82%

CPU load (%) during last 60 seconds:
core 0 1 2 3 4 5
* 83 84 83 84 84

pls check the below KB and verify the outputs.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRTCA0

 

check which interface is utilizing more and is it L2 traffic ? loop?

 

and verify the high idle time out sessions and more info on sessions ids?

 

Best Regards,
Suresh
  • 2065 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!