- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-01-2023 09:40 AM - edited 03-02-2023 12:02 AM
Hi guys,
PA-5250, 9.1.14
Can you help me with this one, please?
PA does not like fragmented SIP INVITE packets, and we can see them in the drop queue:
No traffic, threat or URL filtering logs were created (expected, I believe).
Why is it doing that?
Thanks,
myky
03-08-2023 03:18 AM - edited 03-16-2023 11:12 AM
@Raido_Rattameister correction:
SSD was replaced, and when we failback traffic, the issue returned.
Eventually, TAC confirmed that we hit the following bug:
Same issue, old discussion:
https://www.reddit.com/r/paloaltonetworks/comments/vzrann/panos_9114_software_buffer_depletion/
The bug description is way off.
thanks, myky
03-01-2023 09:52 AM
Do you have Zone Protection applied to zone this traffic comes from?
If you add filter to "Monitor > Packet Capture" to capture traffic from 10.125.3.23 and then run following command in cli what is output? Can you identify based on couters what caused packet drops?
> show counter global filter delta yes packet-filter yes
03-01-2023 11:39 PM - edited 03-02-2023 12:13 AM
Hey @Raido_Rattameister .
Long time!
At one point, I thought that my PA skills completely got rusty, as I believe I have checked that earlier.
There is no ZPP applied; we got only a basic one on the untrusted zone:
thanks,
myky
03-02-2023 05:14 AM
Hey @MykyUk
In this case "show counter global filter delta yes packet-filter yes" is best next step figuring out why they are dropped.
03-02-2023 06:12 AM
Got yah, yes will arrange testing today and update this thread. Thanks! myky
03-02-2023 07:15 AM
@Raido_Rattameister have you seen this before:
I have a feeling it might be a TAC case.
thanks,
myky
03-02-2023 08:59 AM
re-run it again; PA is clearly not happy:
03-08-2023 03:18 AM - edited 03-16-2023 11:12 AM
@Raido_Rattameister correction:
SSD was replaced, and when we failback traffic, the issue returned.
Eventually, TAC confirmed that we hit the following bug:
Same issue, old discussion:
https://www.reddit.com/r/paloaltonetworks/comments/vzrann/panos_9114_software_buffer_depletion/
The bug description is way off.
thanks, myky
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!