Some time ago, I described in a blog post the history of some interesting things. I’m working in the systems integrators environment for more than 12 years, so I have many more such unexpected stories. Let’s elaborate on the next one.
Expect the Unexpected – Palo Alto Networks Logging Capabilities
A Customer had an HA cluster of PANW firewalls. He called me because once in a while, the cluster stops accepting new traffic for about 10-20 minutes. Ongoing sessions are fine, only new ones cannot be established. The case was exactly the same with both members of the active-passive cluster. Sounds interesting… The only thing that was weird was that there were a lot of threat events. Customer had at that time ransomware attack, so the firewall generated a lot of log entries. I followed that path and found quite an interesting setting

Stop Traffic when LogDB Full – that was checked. What happened in detail? As mentioned, a lot of log entries were generated by security events. After a while, the logging disk was almost full, then the firewall stopped accepting new traffic according to the above settings. When the disk is almost full, the firewall automatically starts a job to clear the oldest log entries. In that case, it took about 10-20 minutes.
Palo Alto Networks NGFWs are really granular, with a lot of capabilities and features. However, there are some settings where I cannot find any practical use case. This is one example, why have the capability to stop traffic when the log disk is almost full when the firewall automatically runs a job to free some storage? I don’t know…