- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
09-05-2023 05:39 PM
We've recently deployed PAN-OS 11.0.1-h2 in production on some PA-1400's (terrifying, I know).
Practically, the firewalls seem to be functionally identical to the firewalls they're replacing. However, we've noticed that the "receive errors" counters are incrementing at a steady rate (3-5 per second). We believe the culprit to be the following global counter:
>show counter global filter severity drop delta yes
flow_ingress_ifp_lookup_ifmap_fail
Description: Packets dropped: unable to lookup main interface
Does anyone have any knowledge for what this counter actually records? The counter name and description don't appear to have been documented anywhere (searching for either as a string returns zero results on Google). Our Premium support from PA have failed to acknowledge the existence of these counters, let alone provide any context as to what they record.
09-11-2023 01:22 AM
Hello Simonlaffan,
First of all, running on the 11.0.1-h2 for PA-1400 is almost the recommended action (the only difference between 11.0.1 and 11.0.1-h2 are the hotfixes, unless you affected by one of the 5 fixes, it is roughly the same as 11.0.1 - which is the preferred version).
Regarding the counter, I would suggest to run a pcap (no filter, only the dropped packets) to see what is actually dropped.
(it may be a noise counter).
Olivier
PCSNE - CISSP
Best Effort contributor
Check out our PANCast Channel
Disclaimer : All messages are my personal ones and do not represent my company's view in any way.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!