Slow PA-410

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Slow PA-410

L0 Member

I have everything configured correctly so that I can receive a dynamic IP from the internet provider. The Palo Alto assigns IPs through an access point. Zones are set up correctly.

 

However, the internet is often slow and sometimes painfully slow? We are waiting for more than 10-20 seconds for web pages to load at times. There is no issue without the Palo Alto, so it must be something about how it is set-up.

 

The only thing that we could come up with is that the licenses are not yet assigned to the firewall or this #PA-410 is buggy.

 

Any thoughts?

 

I can provide more context if need be. 

2 REPLIES 2

Cyber Elite
Cyber Elite

@freadmin,

What you're describing kind of sounds like an MTU mismatch is being introduced when you add the firewall. I'd double check your MTU on the ISP equipment and verify that you shouldn't be using a lower MTU size.

L6 Presenter

@freadmin wrote:

I have everything configured correctly so that I can receive a dynamic IP from the internet provider. The Palo Alto assigns IPs through an access point. Zones are set up correctly.

 

However, the internet is often slow and sometimes painfully slow? We are waiting for more than 10-20 seconds for web pages to load at times. There is no issue without the Palo Alto, so it must be something about how it is set-up.

 

The only thing that we could come up with is that the licenses are not yet assigned to the firewall or this #PA-410 is buggy.

 

Any thoughts?

 

I can provide more context if need be. 


Thoughts?  I wouldn't run any firewall in a production environment that didn't have active/entitled licenses.  Not sure if this is or isn't a problem, but it doesn't seem like a good practice.  Is it all traffic that is slow or only some traffic?  I know that on versions <10.2.6 and you're doing SSL inspection HTTPs traffic could be abysmally slow.  (known bug)

As with mentioned by @BPry  maybe there's an MTU mismatch or some other L1/L2 problem like duplex or CRCs?

 

Also what does the CPU stats says on the FW when traffic is slow?  Could you be pushing more traffic through than the box is rated to handle?  Are you running the current preferred code version?  What code are you running?

  • 529 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!