PAN-OS 11 interface counter descriptions

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PAN-OS 11 interface counter descriptions

L0 Member

We've recently deployed PAN-OS 11.0.1-h2 in production on some PA-1400's (terrifying, I know).

 

Practically, the firewalls seem to be functionally identical to the firewalls they're replacing. However, we've noticed that the "receive errors" counters are incrementing at a steady rate (3-5 per second). We believe the culprit to be the following global counter:

 

>show counter global filter severity drop delta yes

flow_ingress_ifp_lookup_ifmap_fail
Description: Packets dropped: unable to lookup main interface

 

Does anyone have any knowledge for what this counter actually records? The counter name and description don't appear to have been documented anywhere (searching for either as a string returns zero results on Google). Our Premium support from PA have failed to acknowledge the existence of these counters, let alone provide any context as to what they record.

1 REPLY 1

L4 Transporter

Hello Simonlaffan,

 

First of all, running on the 11.0.1-h2 for PA-1400 is almost the recommended action (the only difference between 11.0.1 and 11.0.1-h2 are the hotfixes, unless you affected by one of the 5 fixes, it is roughly the same as 11.0.1 - which is the preferred version).

https://live.paloaltonetworks.com/t5/customer-resources/support-pan-os-software-release-guidance/ta-...

 

Regarding the counter, I would suggest to run a pcap (no filter, only the dropped packets) to see what is actually dropped.
(it may be a noise counter). 

 

Olivier

PCSNE - CISSP

Best Effort contributor

Check out our PANCast Channel

Disclaimer : All messages are my personal ones and do not represent my company's view in any way.

  • 714 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!