- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-25-2021 03:22 AM
Hi community
This post is either to inform you about a possible problem and also to ask if someone already saw this and may be even has a solution.
Some days ago the global counter for proxy_wait_pkt_drop started to dramatically increase on a PA-3220 running on PAN-OS 9.1.9. Obviously tls decryption is enbled on this firewall(cluster). The effect of this increasing counter is that for some websites opening them is impossible and for the rest of web-browsing it is generally pretty slow. At the moment I assume there could be a bug in tls proxy which could result in tls proxy process crashes because of tls implementations which may be aren't strictly following RFC guidelines.
Did you already see this in your environment? If not then I recommend keeping an eye on this global counter - specially if you are running a PA-3220 with PAN-OS 9.1.8 or 9.1.9.
Cheers,
Remo
06-23-2021 10:10 AM
To everyone who sees the same problem in their environments: update to 9.1.10 and the problem should be fixed. The reason is because of unavailable CRLs which cause an infinite loop in the sslmgr process which effectively stops the processing of further decrypted sessions. The bug ID of this is PAN-166296
05-25-2021 06:25 PM
@Remo - Thank you for bringing awareness to this!
06-23-2021 10:10 AM
To everyone who sees the same problem in their environments: update to 9.1.10 and the problem should be fixed. The reason is because of unavailable CRLs which cause an infinite loop in the sslmgr process which effectively stops the processing of further decrypted sessions. The bug ID of this is PAN-166296
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!