pa-450 issues and going down 2 days in a row

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

pa-450 issues and going down 2 days in a row

L3 Networker

 all our path monitoring profiles on our ISP links were down even though the ISP was up and we confirmed internet access. There was no ping connectivity from the ISP Firewall Interface to the ISP gateway and we have 3 ISP connection. When we removed the path monitoring profiles on the default route, there was still no connection. Downgrading the firewall firmware version also did not work. Moreover, I already checked some daemons like : chasd, ehmon, data plane, mprelay ,brdagent, messages , but it did not display anything . by any chance that you have any kind of recommendation.

1 accepted solution

Accepted Solutions

L3 Networker

I got the following :

 

[*]2026/03/06 11:30:23 Mar 6 11:30:23 400 kernel: [ 101.984902] igb_uio 0000:07:00.0: uio device registered with irq 165
2026/03/06 11:30:52 Mar 6 11:30:52 400 kernel: [ 130.570408] rte_kni: Creating kni...
2026/03/06 11:30:52 Mar 6 11:30:52 400 kernel: [ 130.571243] rte_kni: Creating kni...
2026/03/06 11:34:50 Mar 6 11:34:50 400 kernel: [ 369.151867] 8021q: 802.1Q VLAN Support v1.8
2026/03/06 11:35:18 Mar 6 11:35:18 400 kernel: [ 396.830018] mmc0: Tuning timeout, falling back to fixed sampling clock
2026/03/06 11:37:57 Mar 6 11:37:57 400 kernel: [ 555.651050] TCP: request_sock_TCP: Possible SYN flooding on port 3099. Sending cookies. Check SNMP counters.
[*]2026/03/06 11:30:23 Mar 6 11:30:23 400 kernel: [ 101.984902] igb_uio 0000:07:00.0: uio device registered with irq 165
2026/03/06 11:30:52 Mar 6 11:30:52 400 kernel: [ 130.570408] rte_kni: Creating kni...
2026/03/06 11:30:52 Mar 6 11:30:52 400 kernel: [ 130.571243] rte_kni: Creating kni...
2026/03/06 11:34:50 Mar 6 11:34:50 400 kernel: [ 369.151867] 8021q: 802.1Q VLAN Support v1.8
2026/03/06 11:35:18 Mar 6 11:35:18 400 kernel: [ 396.830018] mmc0: Tuning timeout, falling back to fixed sampling clock
2026/03/06 11:37:57 Mar 6 11:37:57 400 kernel: [ 555.651050] TCP: request_sock_TCP: Possible SYN flooding on port 3099. Sending cookies. Check SNMP counters.
[*]mprelay.log
[*]2026/03/06 11:31:11 2026-03-06 11:31:11.592 -0400 Error: pan_mprelay_app_dos_init(src/pan_mprelay_dos.c:543): * No hardware ACL capability on this platform !!!*
2026/03/06 11:31:11 2026-03-06 11:31:11.593 -0400 Error: pan_mprelay_event_start(src/pan_mprelay_event.c:209): HW ACL is not supported - skip start acl ager timer
2026/03/06 11:31:11 2026-03-06 11:31:11.594 -0400 Error: pan_chassis_slot_status_fetch(pan_chassis.c:181): cannot find chassis.summary
2026/03/06 11:31:12 2026-03-06 11:31:12.581 -0400 Error: pan_chassis_slot_status_fetch(pan_chassis.c:181): cannot find chassis.summary

View solution in original post

4 REPLIES 4

L3 Networker

I got the following :

 

[*]2026/03/06 11:30:23 Mar 6 11:30:23 400 kernel: [ 101.984902] igb_uio 0000:07:00.0: uio device registered with irq 165
2026/03/06 11:30:52 Mar 6 11:30:52 400 kernel: [ 130.570408] rte_kni: Creating kni...
2026/03/06 11:30:52 Mar 6 11:30:52 400 kernel: [ 130.571243] rte_kni: Creating kni...
2026/03/06 11:34:50 Mar 6 11:34:50 400 kernel: [ 369.151867] 8021q: 802.1Q VLAN Support v1.8
2026/03/06 11:35:18 Mar 6 11:35:18 400 kernel: [ 396.830018] mmc0: Tuning timeout, falling back to fixed sampling clock
2026/03/06 11:37:57 Mar 6 11:37:57 400 kernel: [ 555.651050] TCP: request_sock_TCP: Possible SYN flooding on port 3099. Sending cookies. Check SNMP counters.
[*]2026/03/06 11:30:23 Mar 6 11:30:23 400 kernel: [ 101.984902] igb_uio 0000:07:00.0: uio device registered with irq 165
2026/03/06 11:30:52 Mar 6 11:30:52 400 kernel: [ 130.570408] rte_kni: Creating kni...
2026/03/06 11:30:52 Mar 6 11:30:52 400 kernel: [ 130.571243] rte_kni: Creating kni...
2026/03/06 11:34:50 Mar 6 11:34:50 400 kernel: [ 369.151867] 8021q: 802.1Q VLAN Support v1.8
2026/03/06 11:35:18 Mar 6 11:35:18 400 kernel: [ 396.830018] mmc0: Tuning timeout, falling back to fixed sampling clock
2026/03/06 11:37:57 Mar 6 11:37:57 400 kernel: [ 555.651050] TCP: request_sock_TCP: Possible SYN flooding on port 3099. Sending cookies. Check SNMP counters.
[*]mprelay.log
[*]2026/03/06 11:31:11 2026-03-06 11:31:11.592 -0400 Error: pan_mprelay_app_dos_init(src/pan_mprelay_dos.c:543): * No hardware ACL capability on this platform !!!*
2026/03/06 11:31:11 2026-03-06 11:31:11.593 -0400 Error: pan_mprelay_event_start(src/pan_mprelay_event.c:209): HW ACL is not supported - skip start acl ager timer
2026/03/06 11:31:11 2026-03-06 11:31:11.594 -0400 Error: pan_chassis_slot_status_fetch(pan_chassis.c:181): cannot find chassis.summary
2026/03/06 11:31:12 2026-03-06 11:31:12.581 -0400 Error: pan_chassis_slot_status_fetch(pan_chassis.c:181): cannot find chassis.summary

I got this routed.log :2026/03/06 11:30:42 2026-03-06 11:30:42.476 -0400 Error: pan_routed_chassis_summary_cb(pan_routed_sysd.c:1630): Unable to find traffic_enabled in old list (null) notification
2026/03/06 11:30:42 2026-03-06 11:30:42.476 -0400 Error: pan_routed_chassis_summary_cb(pan_routed_sysd.c:1695): Unable to find config_done in old list (null) notification
2026/03/06 11:30:42 2026-03-06 11:30:42.483 -0400 Error: pan_routed_bind_ev_sock(pan_routed_ev.c:115): bind failed:(errno: 99) Cannot assign requested address
2026/03/06 11:30:42 2026-03-06 11:30:42.484 -0400 Error: frr_vlink_notify_init(pan_routed_ev.c:259): bind failed:(errno: 99) Cannot assign requested address
2026/03/06 11:30:42 2026-03-06 11:30:42.484 -0400 Error: main(pan_routed_main.c:565): frr_vlink_notify_init() failed
2026/03/06 11:30:43 2026-03-06 11:30:43.486 -0400 Error: pan_cfgagent_get_lastcfg(pan_cfgagent.c:1301): Can't fetch last config since data plane doesn't have a config yet
2026/03/06 11:30:43 2026-03-06 11:30:43.489 -0400 Error: pan_routed_cfg_if_info_refresh(pan_routed_cfg.c:9368): Can't sysd_fetch_obj cfg.general.interface-process-delay (NO_MATCHES)
2026/03/06 11:30:50 2026-03-06 11:30:50.013 -0400 Error: pan_dnsproxy_fqdn_sysd_notify_status_cb(pan_dnsproxy_fqdn.c:1515): notify obj sw.dnsproxyd.fqdn-api.routed.status, event update unhandled!
2026/03/06 11:31:08 2026-03-06 11:31:08.503 -0400 Error: pan_routed_cluster_is_enabled(pan_routed_cluster.c:139): curcfg is not available

 

documentation said that 11.1.1.3 is considered a bug , but I do not get bug number a;bout a multi ISP issues . by any chance that you have a bug number about it.

I almost forgot that the problem started on 11.1.4-h7 and then it was solved when upgraded to 11.1.13 . Now we visualize that this is a brute force attack based on the following log :

 

Me parece que el firewall se murio por un ataque de fuerza bruta amigo:

 

2026/03/06 11:25:25 medium   auth                      Remote auth-fail                 0  failed authentication for user 'qqqwww'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:25:24 medium   auth                      Remote auth-fail                 0  failed authentication for user 'boobies'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:25:23 medium   auth                      Remote auth-fail                 0  failed authentication for user 'richard1'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:25:21 medium   auth                      Remote auth-fail                 0  failed authentication for user 'familia'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:25:20 medium   auth                      Remote auth-fail                 0  failed authentication for user '12345qwer'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:25:20 medium   auth                      Remote auth-fail                 0  failed authentication for user 'kkkkkkkk'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:25:19 medium   auth                      Remote auth-fail                 0  failed authentication for user 'poop123'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:25:19 info     general                          general                   0  Installed panos software version 11.1.13

 

2026/03/06 11:25:17 medium   auth                      Remote auth-fail                 0  failed authentication for user 'darren'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:25:17 medium   auth                      Remote auth-fail                 0  failed authentication for user 'administrator'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 185.156.73.62.

 

2026/03/06 11:25:16 medium   auth                      Remote auth-fail                 0  failed authentication for user 'administrator'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 185.156.73.62.

 

2026/03/06 11:25:15 medium   auth                      Remote auth-fail                 0  failed authentication for user 'administrator'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 185.156.73.62.

 

2026/03/06 11:25:14 medium   auth                      Remote auth-fail                 0  failed authentication for user 'cmiller'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.138.

 

2026/03/06 11:25:14 medium   auth                      Remote auth-fail                 0  failed authentication for user 'gagaga'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:54 medium   auth                      Remote auth-fail                 0  failed authentication for user '2004'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:51 medium   auth                      Remote auth-fail                 0  failed authentication for user '555556'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:50 medium   auth                      Remote auth-fail                 0  failed authentication for user 'hendrix'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:47 medium   auth                      Remote auth-fail                 0  failed authentication for user '6666666'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:46 medium   auth                      Remote auth-fail                 0  failed authentication for user 'abrakadabra'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:46 medium   auth                      Remote auth-fail                 0  failed authentication for user 'dinosaur'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:43 medium   auth                      Remote auth-fail                 0  failed authentication for user 'Pa55w0rd'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:24:41 medium   auth                      Remote auth-fail                 0  failed authentication for user 'asdasd1'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:39 medium   auth                      Remote auth-fail                 0  failed authentication for user 'hendrix'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:38 medium   auth                      Remote auth-fail                 0  failed authentication for user 'adidas123'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:24:38 medium   auth                      Remote auth-fail                 0  failed authentication for user 'dinosaur'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:37 info     url-filtering                    upgrade-url-databas       0  PAN-DB was upgraded to version 20260306.20232.

 

2026/03/06 11:24:36 medium   auth                      Remote auth-fail                 0  failed authentication for user 'commando'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:24:33 medium   auth                      Remote auth-fail                 0  failed authentication for user 'hendrix'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:32 medium   auth                      Remote auth-fail                 0  failed authentication for user 'joejoe'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:24:29 medium   auth                      Remote auth-fail                 0  failed authentication for user 'leavemealone'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:29 medium   auth                      Remote auth-fail                 0  failed authentication for user 'michigan'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:24:28 medium   auth                      Remote auth-fail                 0  failed authentication for user 'leavemealone'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:26 medium   auth                      Remote auth-fail                 0  failed authentication for user 'maddie'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:26 medium   auth                      Remote auth-fail                 0  failed authentication for user 'muhammad'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:24:25 medium   auth                      Remote auth-fail                 0  failed authentication for user 'maddie'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:23 medium   auth                      Remote auth-fail                 0  failed authentication for user 'qwerasdfzxcv'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:24:23 medium   auth                      Remote auth-fail                 0  failed authentication for user 'marcos'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:21 medium   auth                      Remote auth-fail                 0  failed authentication for user 'rooney'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:24:19 medium   auth                      Remote auth-fail                 0  failed authentication for user 'scooter1'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:24:19 medium   auth                      Remote auth-fail                 0  failed authentication for user 'nanana'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:16 medium   auth                      Remote auth-fail                 0  failed authentication for user '123123321'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:14 medium   auth                      Remote auth-fail                 0  failed authentication for user '123456k'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:24:00 medium   auth                      Remote auth-fail                 0  failed authentication for user '654123'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:58 medium   auth                      Remote auth-fail                 0  failed authentication for user 'kaka123'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:58 medium   auth                      Remote auth-fail                 0  failed authentication for user 'robinhood'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:57 medium   auth                      Remote auth-fail                 0  failed authentication for user 'skorpion'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:57 medium   auth                      Remote auth-fail                 0  failed authentication for user '98765'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:54 medium   auth                      Remote auth-fail                 0  failed authentication for user '1001'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:48 medium   auth                      Remote auth-fail                 0  failed authentication for user 'xxx123'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:46 medium   auth                      Remote auth-fail                 0  failed authentication for user '123qwe456'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:23:44 medium   auth                      Remote auth-fail                 0  failed authentication for user '1001'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:43 medium   auth                      Remote auth-fail                 0  failed authentication for user '1357908642'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:23:42 medium   auth                      Remote auth-fail                 0  failed authentication for user '1a2a3a4a'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:39 medium   auth                      Remote auth-fail                 0  failed authentication for user '1a2a3a4a'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:37 medium   auth                      Remote auth-fail                 0  failed authentication for user 'cassandra'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:23:35 medium   auth                      Remote auth-fail                 0  failed authentication for user '78787878'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:35 medium   auth                      Remote auth-fail                 0  failed authentication for user '78787878'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:34 medium   auth                      Remote auth-fail                 0  failed authentication for user 'mikemike'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:23:31 medium   auth                      Remote auth-fail                 0  failed authentication for user 'musica'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:23:31 medium   auth                      Remote auth-fail                 0  failed authentication for user 'spartan117'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:23:31 medium   auth                      Remote auth-fail                 0  failed authentication for user '98765'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:26 medium   auth                      Remote auth-fail                 0  failed authentication for user '999666'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:25 medium   auth                      Remote auth-fail                 0  failed authentication for user '999666'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:24 medium   auth                      Remote auth-fail                 0  failed authentication for user 'wonderful'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:23:24 medium   auth                      Remote auth-fail                 0  failed authentication for user '123456@'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:23:23 medium   auth                      Remote auth-fail                 0  failed authentication for user 'sammy123'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:23 medium   auth                      Remote auth-fail                 0  failed authentication for user 'bulldogs'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:20 medium   auth                      Remote auth-fail                 0  failed authentication for user '1qw23er4'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:23:18 medium   auth                      Remote auth-fail                 0  failed authentication for user 'gabriel1'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:14 medium   auth                      Remote auth-fail                 0  failed authentication for user 'julia'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:23:09 info     ntpd                             restart                   0  NTP restart synchronization performed

 

2026/03/06 11:22:52 medium   ntpd                             auth                      0  NTP sync to server 172.45.82.51 failed, authentication type none

 

2026/03/06 11:22:52 medium   ntpd                             auth                      0  NTP sync to server 172.45.82.50 failed, authentication type none

 

2026/03/06 11:22:46 medium   auth                      Remote auth-fail                 0  failed authentication for user 'pekanbaru'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 92.63.197.23.

 

2026/03/06 11:22:44 medium   auth                      Remote auth-fail                 0  failed authentication for user 'pekanbaru'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 92.63.197.23.

 

2026/03/06 11:22:44 medium   auth                      Remote auth-fail                 0  failed authentication for user 'tototo'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:22:43 medium   auth                      Remote auth-fail                 0  failed authentication for user '12345123'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:22:42 medium   auth                      Remote auth-fail                 0  failed authentication for user 'lacrosse'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:40 medium   auth                      Remote auth-fail                 0  failed authentication for user 'pekanbaru'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 92.63.197.23.

 

2026/03/06 11:22:39 medium   auth                      Remote auth-fail                 0  failed authentication for user 'piglet'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:37 medium   auth                      Remote auth-fail                 0  failed authentication for user '19191919'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:22:37 medium   auth                      Remote auth-fail                 0  failed authentication for user '373737'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:22:35 medium   auth                      Remote auth-fail                 0  failed authentication for user 'sporting'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:33 medium   auth                      Remote auth-fail                 0  failed authentication for user 'sporting'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:33 medium   auth                      Remote auth-fail                 0  failed authentication for user 'Admin123'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:22:32 medium   auth                      Remote auth-fail                 0  failed authentication for user 'star'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:30 medium   auth                      Remote auth-fail                 0  failed authentication for user 'star'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:28 medium   auth                      Remote auth-fail                 0  failed authentication for user 'Password12'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:22:28 medium   auth                      Remote auth-fail                 0  failed authentication for user '420420'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:28 medium   auth                      Remote auth-fail                 0  failed authentication for user '420420'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:27 medium   auth                      Remote auth-fail                 0  failed authentication for user 'america1'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:22:25 medium   auth                      Remote auth-fail                 0  failed authentication for user 'bigboss'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:24 medium   auth                      Remote auth-fail                 0  failed authentication for user 'bigboss'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:24 medium   auth                      Remote auth-fail                 0  failed authentication for user 'handsome'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:23 medium   auth                      Remote auth-fail                 0  failed authentication for user 'cartoon'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:22:23 medium   auth                      Remote auth-fail                 0  failed authentication for user 'ssssssss'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:22 medium   auth                      Remote auth-fail                 0  failed authentication for user 'blaster'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:22 medium   auth                      Remote auth-fail                 0  failed authentication for user 'colombia'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:21 medium   auth                      Remote auth-fail                 0  failed authentication for user 'blaster'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:19 medium   auth                      Remote auth-fail                 0  failed authentication for user 'cherokee'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 86.54.24.141.

 

2026/03/06 11:22:18 medium   auth                      Remote auth-fail                 0  failed authentication for user 'colombia'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:17 medium   auth                      Remote auth-fail                 0  failed authentication for user 'coucou'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:14 medium   auth                      Remote auth-fail                 0  failed authentication for user 'coucou'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:14 medium   auth                      Remote auth-fail                 0  failed authentication for user 'handsome'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:12 info     userid                    172.45 connect-ldap-sever        0  ldap cfg AP Scott Group connected to server 172.45.82.51:389, initiated by: 172.45.82.11

 

2026/03/06 11:22:08 medium   auth                      Remote auth-fail                 0  failed authentication for user 'shithead'.  Reason: User is not in allowlist. auth profile 'Remote Users LDAP', vsys 'vsys1', From: 178.20.210.172.

 

2026/03/06 11:22:00 medium   auth            

 

Observa los nombres de usuario y ya llevan un mes así, mi teoria es que agotaron los recursos de management y la tiraron 

 

O saturaron algun canal del firewall y los 3 ISP caen simultaneos 

 

2026/03/05 13:06:33 critical routing                   defaul path-monitor-failur       1  Path monitoring failed for static route destination 0.0.0.0/0 with next hop 186.96.216.125. Route removed.

 

2026/03/05 13:06:33 critical routing                   defaul path-monitor-failur       1  Path monitoring failed for static route destination 0.0.0.0/0 with next hop 190.213.36.1. Route removed.

 

2026/03/05 13:06:33 critical routing                   defaul path-monitor-failur       1  Path monitoring failed for static route destination 0.0.0.0/0 with next hop 131.100.36.159. Route removed.

 

2026/03/05 13:06:25 medium   dns-security              dns-si PAN_ELOG_EVENT_DNS_       0  DNS Security cloud query timeout.

 

2026/03/05 13:06:15 medium   dns-security              dns-si PAN_ELOG_EVENT_DNS_       0  DNS telemetry cloud service network connectivity failed.

 

 

 

L3 Networker

Hello,

Try to open a TAC case first. Without others information, it will be hard to help you.

Is it possible to see what happened in the system logs before the path monitoring going down? 

Can you try these commands : 

show counter global | match dos

show session packet-buffer-protection

show running resource-monitor
show running resource-monitor ingress-backlogs

 

Best regards,

 

  • 1 accepted solution
  • 1303 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!