resources-unavailable for DNS-base traffic

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

resources-unavailable for DNS-base traffic

L1 Bithead

Model: Palo Alto PA-3420
Software version: 11.2.4-h1

 

Most of our dns-base traffic has the "session end reason" resources-unavailable suddenly. We're also having trouble loading webpages. The resources-unavailable reason is only on DNS-base traffic and it is for DNS traffic to our 2 internal DNS servers, but also from our DNS-server to the forwarders or directly to external DNS server (for example 8.8.4.4, 8.8.8.8).

I checked the commands "show counter global name aho_alloc_lookup_failed":

Name:           aho_alloc_lookup_failed
Value:          0
Severity:       Warning
Category:       aho
Aspect:         resource
Description:    failed to alloc regex lookup

 And "debug dataplane pool statistics | match "Regex Results"":

[18] Regex Results (  16352): 2048/2048  52/2048  1/1      0xd301603b00-0xd3035f3b00  52

But that seems ok. Any suggestions what can be wrong, or where I can look?

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello,

Check the unified logs to see where/if the traffic is getting blocked. Its UDP so might have to check the session browser, if the session is still open it wont show in the logs (reason 'log at session end' on the security policy).

 

Regards,

 

Regards,

L1 Bithead

The traffic is allowed:

 

631.png

 

It seems like some sort of memory leak affecting only the DNS traffic. We had to restart the firewall because normal internet was impossible with all the failed DNS requests. After the reboot we haven't seen any "session end reason: resource-unavailable" anymore. The uptime before the reboot was 61 days, so not that long.

  • 387 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!