- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
08-13-2024 02:59 AM
Hi!
Me again, I apologize. I am currently out of troubleshooting tricks.
So here it is. I have configured my Source NAT, outbound-to-internet and default route. All are good. No issue. Traffic is hitting the correct Rule and NAT.
The thing is, the webpages are very slow as they loads. Probably 2mins or more. Kind of frustrating and time-consuming.
I tried running the global counters and the attached are what i found. I already ran the asymmetric bypass and tcp non syn reject from this article (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClSHCA0) but still no good.
I am kind of puzzled since my ISP is good and no issue.
What could it be?
Thank you in advanced!
08-13-2024 10:10 AM
What version of PAN-OS are you running? There is a bug with Inline Cloud filtering enabled that causes almost exactly a 2 minute delay in some website access. The fix is either to turn off the inline cloud filtering OR add a whitelist to the inline cloud filter and whitelist sites you have issues with. We run 10.2.9-h3 and have been waiting for a fix. The fix was in a later release but they had more severe issues in their fixes so are waiting for 10.2.10-h3 or 10.2.9-h9 to go preferred so we can upgrade to them.
See this:
PAN-251895
|
Fixed an issue where enabling inline Cloud Analysis features caused a slow packet buffer leak, which resulted in performance issues and dropped traffic.
|
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!