cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

Knowledge sharing: High Data Plane CPU because of DDOS or overutilization (access to Palo Alto Auto Assistant may help)

L6 Presenter

I have seen for example on a small firewall when the customer enables SSL decryption that the counters for work groups "ecdhe_key_gen", "flow_host " etc. jump. This may show that the firewall can't handle the ssl decryption or that there is an SSL DDOS attack:

 

 

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CmV2CAK

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXwCAK

 

 

 

 

If you have access to the Palo Alto Auto Assistant tool (like F5 ihealth but for some reason Palo Alto gives access to this tool only to Partners) you can use it to better view such issue from the Tech support file. Otherwise use the logs and global counters in the articles I provided.

 

 

For more about Palo Alto logs and their meaning you can view:

 

https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-general-logs-and-log...

 

 

Who rated this post