resources-unavailable for DNS-base traffic

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

resources-unavailable for DNS-base traffic

L1 Bithead

Model: Palo Alto PA-3420
Software version: 11.2.4-h1

 

Most of our dns-base traffic has the "session end reason" resources-unavailable suddenly. We're also having trouble loading webpages. The resources-unavailable reason is only on DNS-base traffic and it is for DNS traffic to our 2 internal DNS servers, but also from our DNS-server to the forwarders or directly to external DNS server (for example 8.8.4.4, 8.8.8.8).

I checked the commands "show counter global name aho_alloc_lookup_failed":

Name:           aho_alloc_lookup_failed
Value:          0
Severity:       Warning
Category:       aho
Aspect:         resource
Description:    failed to alloc regex lookup

 And "debug dataplane pool statistics | match "Regex Results"":

[18] Regex Results (  16352): 2048/2048  52/2048  1/1      0xd301603b00-0xd3035f3b00  52

But that seems ok. Any suggestions what can be wrong, or where I can look?

7 REPLIES 7

Cyber Elite
Cyber Elite

Hello,

Check the unified logs to see where/if the traffic is getting blocked. Its UDP so might have to check the session browser, if the session is still open it wont show in the logs (reason 'log at session end' on the security policy).

 

Regards,

 

Regards,

L1 Bithead

The traffic is allowed:

 

631.png

 

It seems like some sort of memory leak affecting only the DNS traffic. We had to restart the firewall because normal internet was impossible with all the failed DNS requests. After the reboot we haven't seen any "session end reason: resource-unavailable" anymore. The uptime before the reboot was 61 days, so not that long.

Any info on the cause? We've had this occur twice now, 14 days apart. A reboot was the only solution. I haven't opened a case yet, but that's my next step.

L4 Transporter

Hi @adminglu ,

 

Recommendation is to open a support case and work with tac team to identify the issue.

Best Regards,


Mohammad Talib

Don't forget to Like items if a post is helpful to you!
Please help out other users and “Accept as Solution” if a post helps solve your problem!

Disclaimer: All messages are my personal ones and do not represent my company's view in any way.

After 21 days uptime the issue came back. This friday I have to install an update on the firewall so the problem will be gone for a while. If it comes back again I'm going to create a support ticket with Palo Alto.

L0 Member

Just want to share for my case is PA440 , opened with support and they request to enable the Jumbo frame support in PA to avoid this issue . 

Thanks for reporting back, we just had the issue again yesterday after 72 days uptime.

 

You mean under Device->Setup->Session->Session Settings->Enable Jumbo Frame?

  • 3094 Views
  • 7 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!