PAN-OS 7.1.4-H2 Data filtering and Url filtering logging stops at serveral hours+ SSL decrypt fails

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PAN-OS 7.1.4-H2 Data filtering and Url filtering logging stops at serveral hours+ SSL decrypt fails

L3 Networker

We upgraded a VM100 from PAN-OS 7.0.8 to PAN-OS 7.1.4 H2.

We had 0 issues running 7.0.8 but we needed the DHE en EHCDE cipher support

 

Now we have the issue that the Data filtering and Url filtering logging stops at serveral hours.

Also some https sites starting to become very slow ands ssl decryption starting to fail for some websites.

The vm100(4cpu) is under medium load  and dataplane  cpu usage average 30-40 % 

 

The only way to get it working  again for x hours is to reboot the VM-100 

I cannot reproduce these issues in our lab environment.

 

Someone else experience the same bug/behaviour?

 

1 accepted solution

Accepted Solutions

L3 Networker

My Issue is fixed in PAN-OS 7.1.5 :

 

PAN-61815 Fixed a rare issue where VM-Series firewalls stopped generating traffic, threat or URL logs, or lost the ability to resolve the URL category.

View solution in original post

4 REPLIES 4

L7 Applicator
I've seen the same issue. Are you running HA pair of VMs or just a single standalone firewall? I was previously running 7.1.3 and had issues with 7.1.4. I ended up rolling back. Similar symptoms: URL logging stops completely and some well-known urls incorrectly show up as "unknown"

Open a case with TAC so you can track the progress on this one.

Thanks for your reply.

 

Single VM. do you have a TAC case open? 

I did have a case open, 00533543, but it was mapped to a VM-Series HA bug.  With you running a single VM-Series and seeing these symptoms, I would definitely recommend opening a case.  Feel free to reference mine for the similar symptom of URL logging stopping completely.  Let me know what your case # is as well and I'll update my TAC engineer with that info.  

L3 Networker

My Issue is fixed in PAN-OS 7.1.5 :

 

PAN-61815 Fixed a rare issue where VM-Series firewalls stopped generating traffic, threat or URL logs, or lost the ability to resolve the URL category.

  • 1 accepted solution
  • 3362 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!