Performance Problem with PA 500

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Performance Problem with PA 500

L3 Networker

I recently upgraded my bandwidth to fiber with my provider.  They added a router in the mix that was not there.  It has an external IP and and internal IP address.  The old setup only had an external IP (which is the IP that was configured in my firewall natting rules.)  My upload speed is around 90mb, but the download speed is not even 5mb.  .  We set all settings as the isp requested.  100mbps ad Full Duplex, on the firewall and switch.  The path is. Fiber comes in to ISP Switch --> ISP Router --> Juniper Switch --> Firewall.

After trying everything we could think of I took the main PA500 offline and brought the HA1 online to take over.  Speeds hit 75-80 mb both ways.  This lasted a few hours until downloads started dragging again.   I cleared the logs and speeds shot back up.  We are able to isolate the problem in the firewall.  What is causing my performance issues.  The HA is configured exactly like the primary, which is still offline.  All ideas are appreciated.


L7 Applicator

Hello Sir,

Are you using any specific protocol to measure the speed or just using free tools, i.e.

The first step is to isolate where the performance issue is occurring due to:

Data Plane (DP) CPU

Packet Buffers


Management Plane (MP)

Most handy command will be :PAN> > show system statistics session

> show running resource-monitor

a. Check the CPU load during the last 60 seconds. If any number is at or close to 100, then high CPU is likely the cause of the performance issue.

b. Check the "packet buffer" and "packet descriptor" sections. If any number is at or close to 100, then the issue is likely caused by running out of packet buffers.

c. Check the session section. If any number is close to or above 80, then the performance issue is most likely session related.

Few more commands:

> debug dataplane pool statistics

> show session info

Hope this helps.


I am using a few different web sites to test speed, the same ones the ISP uses.  You know how they are, We can see the router and are sending 100 mgs so it must be on your end.Event they care not seeing 100 mgs which is what the fiber is supposed to be hitting.. I will test the commands you submitted.  After further measuring throughout today we are averaging 80-85.  Is it possible something has stabilize?

We need to check the firewall while the problem occurs, just to confirm if the PAN is causing the latency. Could you please analyze the ACC report during that time, anything looking abnormal..?


I agree with Hulk that you will need to gather data when the issue is occurring.  The top candidates for me would be cpu issues or resource exhaustion.  These are checked with:

show running resource-monitor

debug dataplane pool statistics

On possible cause of these issues could be a threat or a ddos attack.

Another good test would be if you can get a laptop into that on the Juniper switch between the ISP router and the Palo Alto if an address is available.  Then run the download test from here during the issue.  This will eliminate the PA from the loop and do a test during the incident for possible outside influences or a transient ISP issue that they don't see because it is gone when they investigate but there during your problems.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
  • 4 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!