Does Inter-VSYS traffic get offloaded?

Does Inter-VSYS traffic get offloaded?

7212
Created On 01/16/20 00:33 AM - Last Modified 07/30/20 01:57 AM


Question


Does Inter-VSYS traffic get offloaded?

Environment


  • All Palo Alto Firewalls.
  • PAN-OS 7.1, 8,1, 9.0.


Answer


  • Inter-VSYS traffic does not get offload.
  • If Inter-VSYS traffic is coming in at high rate, it can cause memory to go high which can result in high Dataplane CPU. This in turn can cause firewall to experience latency or slowness.
  • One of the workaround is to  move multiple interfaces in different VSYS to use the same VSYS. Another workaround is to reduce traffic between Inter VSYS.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000POFI&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FkCSArticleDetail%3Fid%3DkA10g000000POFI

Choose Language