<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="https://www.staffordnet.uk/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="https://www.staffordnet.uk/feed.php">
        <title>Saucepan - paloaltonetworks:troubleshooting</title>
        <description></description>
        <link>https://www.staffordnet.uk/</link>
        <image rdf:resource="https://www.staffordnet.uk/lib/exe/fetch.php?media=favicon.ico" />
       <dc:date>2026-04-05T20:05:22+00:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:certificates&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:decryption&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:disk_space&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:firewall_resources&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:flow_basic&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:global_protect&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:logs&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:misc&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:packet_captures&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:restart_panos&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:sip&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:stats_dump&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:technical_support_file&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:testing_panos&amp;rev=1674320089&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:unlock_accounts&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:vpn&amp;rev=1669207782&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:web_ui&amp;rev=1669207782&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="https://www.staffordnet.uk/lib/exe/fetch.php?media=favicon.ico">
        <title>Saucepan</title>
        <link>https://www.staffordnet.uk/</link>
        <url>https://www.staffordnet.uk/lib/exe/fetch.php?media=favicon.ico</url>
    </image>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:certificates&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>certificates</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:certificates&amp;rev=1669207782&amp;do=diff</link>
        <description>Certificates

Request New Device Certificate

request certificate fetch</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:decryption&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>decryption</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:decryption&amp;rev=1669207782&amp;do=diff</link>
        <description>Troubleshooting Decryption

decrypt-cert-validation

Remember, if you block users from accessing sites with expired certificates (even if this is just set in the “no-decrypt” section), you will get  ( session_end_reason eq decrypt-cert-validation )</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:disk_space&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>disk_space</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:disk_space&amp;rev=1669207782&amp;do=diff</link>
        <description>Disk Space Maintenance

Show Disk Space

You can verify how much disk space is free with this command

show system disk-space

Delete Saved Configuration Files

To delete a named configuration on PAN-OS, SSH in to the CLI and run the following command</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:firewall_resources&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>firewall_resources</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:firewall_resources&amp;rev=1669207782&amp;do=diff</link>
        <description>Troubleshooting Firewall Performance

CPU Spikes

Could be caused by genindex.sh.

Could be caused by IPsec tunnels.

Performance Issues

Possible but in PAN-OS 10.0.6 but we have seen a case where disabling “Forward segments exceeding TCP content inspection queue” cause massive throughput hit.</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:flow_basic&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>flow_basic</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:flow_basic&amp;rev=1669207782&amp;do=diff</link>
        <description>Flow Basic Steps

Apply the filters from &#039;Monitor &gt; Packet Capture&#039;

Filters:

	*  Source=Client IP - Destination=Server IP
	*  Source=Server IP - Destination= Client IP
	*  Source=NAT IP - Destination=Server IP
	*  Source=Server IP - Destination=NAT IP</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:global_protect&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>global_protect</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:global_protect&amp;rev=1669207782&amp;do=diff</link>
        <description>Troubleshooting GlobalProtect

Client Logs

	*  PanGP Agent logs are for the GlobalProtect UI program
	*  PanGP Service logs are for the GlobalProtect service/daemon program. Use this one.

PanGP Service Logs

Sections of Service Logs

	*  ----portal processing starts</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:logs&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>logs</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:logs&amp;rev=1669207782&amp;do=diff</link>
        <description>Troubleshooting Logs

View Daemon Logs

To view the PHP web server logs on a Palo

tail follow yes mp-log php.debug.log

To view the VPN logs on a Palo

tail follow yes mp-log ikemgr.log

Logging Rates

See here.
Show firewall logging rate

debug log-receiver statistics</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:misc&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>misc</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:misc&amp;rev=1669207782&amp;do=diff</link>
        <description>PAN-OS Misc Troubleshooting

Memory Error

I once had an issue where a Palo would commit fine until I started using the certificates it had installed. (e.g. added a GlobalProtect Portal).

At that point I would fail to commit with the message 

Error: Certificate &#039;cert name&#039; failed to load: Internal memory error.</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:packet_captures&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>packet_captures</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:packet_captures&amp;rev=1669207782&amp;do=diff</link>
        <description>Packet Captures

Packet Capture Types

	*  RX - Pre-decryption, pre-NAT
	*  FW - Post-decryption, pre-NAT
	*  TX - Post-decryption, post-NAT
	*  DR - Dropped packets 

Putting RX and TX into the same file will, if NAT is involved, result in the packet capture putting both the pre-NAT packet and the post-NAT packet in the PCAP. Including the FW stream will result in duplicate errors as it will clash with RX.</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:restart_panos&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>restart_panos</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:restart_panos&amp;rev=1669207782&amp;do=diff</link>
        <description>Restart Software

Restart Entire Device

request restart system

request shutdown system

Restart Management Plane Only

debug software restart device-server
debug software restart management-server

Later versions of code use:

debug software restart process management-server</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:sip&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>sip</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:sip&amp;rev=1669207782&amp;do=diff</link>
        <description>SIP

This link is very good. 

	*  Create a custom app that is TCP/UDP 5060.
	*  Create and App-ID override policy for TCP 5060 and set it to this app.
	*  Create and App-ID override policy for UDP 5060 and set it to this app.

I have seen this fix an issue where the call was made but audio didn&#039;t work for 10 seconds (also, dial back wasn&#039;t audible during calling).</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:stats_dump&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>stats_dump</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:stats_dump&amp;rev=1669207782&amp;do=diff</link>
        <description>Stats Dump

scp export stats-dump start-time equal 2017/04/04@00:00:00 end-time equal 2017/MONTH/DAY@00:00:00 to USERNME@IPADDRESS:/PATH/FILENAME

or

tftp export stats-dump start-time equal 2011/11/15@00:00:00 end-time equal 2011/12/05@00:00:00 to YOUR_PC_IP_ADDR</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:technical_support_file&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>technical_support_file</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:technical_support_file&amp;rev=1669207782&amp;do=diff</link>
        <description>Technical Support File

Device State File

Device Group Data

device_state_cfg\device_state_cfg\sp\vsys1\sp-config.xml

Template Data

device_state_cfg\device_state_cfg\template\template-config.xml

Local Data
&lt;code&gt;device_state_cfg\device_state_cfg\running-config.xml&lt;code&gt;</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:testing_panos&amp;rev=1674320089&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2023-01-21T16:54:49+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>testing_panos</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:testing_panos&amp;rev=1674320089&amp;do=diff</link>
        <description>Testing PAN-OS

This page lists various methods for testing configuration on a Palo Alto Networks firewall

Set VSYS

If you are working on a multi-vsys appliance, use the following command to switch to the appropriate vsys.

set system setting target-vsys &lt;vsys-name&gt;</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:unlock_accounts&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>unlock_accounts</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:unlock_accounts&amp;rev=1669207782&amp;do=diff</link>
        <description>Unlock Accounts

You can unlock an account on the CLI

request authentication unlock-admin user &lt;value&gt;</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:vpn&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>vpn</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:vpn&amp;rev=1669207782&amp;do=diff</link>
        <description>IPSec VPN Troublshooting

Remember, VM Series firewalls can only handle 300Mbps each way (600Mbps total) per Ipsec tunnel. This is due to the PAN-OS archtiecture. This does not affect hardware firewalls.
More info here and here.

Test All VPN Connections

test vpn ipsec-sa</description>
    </item>
    <item rdf:about="https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:web_ui&amp;rev=1669207782&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2022-11-23T12:49:42+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>web_ui</title>
        <link>https://www.staffordnet.uk/doku.php?id=paloaltonetworks:troubleshooting:web_ui&amp;rev=1669207782&amp;do=diff</link>
        <description>PAN-OS Web UI

In the PAN-OS Web GUI, type CTRL+ALT+X to bring up the debug window.</description>
    </item>
</rdf:RDF>
