Hello Bino, Before re-start the PAN firewall, i would request you to follow below mentioned steps: Question-1: >show logging-status Check: Last Log fwded and Last SeqNo. fwded counters. Make sure dates are showing correctly and sequence number is incrementing. >debug log-receiver statistics Check Log incoming rate and Log written rate are incrementing. Make sure below mentioned counters are not incrementing rapidly: Log Forward discarded (queue full) count: 0 >>>>>> Log Forward discarded (send error) count: 0 >>>>>> Apply below mentioned command as per the sequence: >debug software trace log-receiver >debug software trace management-server >debug software restart log-receiver if no change still; >debug software restart management-server Once you will restart the management-server process, it will take some time to come up, you will lose cli access for a few minutes and it will not impact to the production traffic through data-plane. > debug dataplane pool statistics >>>>>>>>> Verify Software pools are not depleted > show system software status | match logrcvr ( Restart may be required if not running/stopped) Question-2: If the PA-500 HA pair is in a production environment, i would suggest you not to restart both firewalls at the same time. First restart the Active firewall, so the Secondary will become Active ( for the time being) and it will start passing production traffic. Once, it will become up, you may restart the second firewall. Please let me know, if you have any other questions or concerns I can help address regarding this issue. Thanks
... View more