This post is either to inform you about a possible problem and also to ask if someone already saw this and may be even has a solution.
Some days ago the global counter for proxy_wait_pkt_drop started to dramatically increase on a PA-3220 running on PAN-OS 9.1.9. Obviously tls decryption is enbled on this firewall(cluster). The effect of this increasing counter is that for some websites opening them is impossible and for the rest of web-browsing it is generally pretty slow. At the moment I assume there could be a bug in tls proxy which could result in tls proxy process crashes because of tls implementations which may be aren't strictly following RFC guidelines.
Did you already see this in your environment? If not then I recommend keeping an eye on this global counter - specially if you are running a PA-3220 with PAN-OS 9.1.8 or 9.1.9.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!