Slow VPN throughput after update to 5.0.7

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Slow VPN throughput after update to 5.0.7

L1 Bithead

Hello Community

Has anyone recognized some performance issues (extremely slow ip-sec throughput, hanging sessions) after updating to 5.0.7

A Firewall reboot solves this issue, but it's coming up again after some days.

Many thanks

Hannes

1 ACCEPTED SOLUTION

Accepted Solutions

Hello Ianhan,


As Apasupulati explain about the buffer functionality in PAN-OS very well on above post. So, once the buffer will exhaust ( 1/8192     0x80000000bb410700 ), all incoming/outgoing packet will be in queue for a long time to allocate packet buffer for further processing. As a result you will see an unexpected delay / slowness of traffic processing. Every time you will reboot this firewall, the packet buffer counter will reset to normal ( 8134/8192     0x80000000bb410700).


The PAN engineering team has already identified the issue with this version PAN-5.0.7 and fixed in a temp-fix version. For better and longer stability, i would recommend you to upgrade the PAN-OS of this firewall.


Hope this helps.


Thanks

View solution in original post

14 REPLIES 14

L7 Applicator

Hello Hannes,

Could you please apply below mentioned command after every 10 minutes and share the o/p with us.

> debug data-plane pool statistics

> show system statistics session

> show running resource-monitor

Thanks

Hello.

We have same performance after update from 5.0.5 so no performance issue.

Check on PA-2050, PA-500 and PA-200

L5 Sessionator

Please run the following commands and show the entire output. The sample out would seem something like below and more.

admin@500> debug dataplane pool statistics

Verify Software pools are not depleted:

Software Pools

[ 0] software packet buffer 0  : 16384/16384    0x8000000021800680

[ 1] software packet buffer 1  : 8192/8192     0x8000000022010700

[ 2] software packet buffer 2  : 8192/8192     0x8000000022818780

[ 3] software packet buffer 3  : 4096/4096     0x8000000023820800

When the issue is happening If by any chance the number is reaching to 1 that would indicate that some buffer is leaking. If this is the case you will need to open a case with Tech support to further investigate the issue.

Hope this helps.

Thanks

L4 Transporter

Upgraded our 3050 pair 2 weeks ago and have not heard of any issues with VPN yet.  Will keep monitoring now.  Resources appear in good shape.  Thanks!

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!