Simultaneous file downloads are failing when using any security profile along with decryption on the security rule.

Simultaneous file downloads are failing when using any security profile along with decryption on the security rule.

10945
Created On 04/11/22 04:53 AM - Last Modified 11/02/22 04:43 AM


Symptom


  • File downloads either fail or the downloaded files are corrupted and fail the CRC check.
  • The issue is usually observed when multiple files are downloaded simultaneously.
  • Disabling the SSL decryption fixes the issue
  • Keep the SSL decryption enabled but removing all the security profile from security rule also fixes the issue. 
  • No Threat logs are generated for this issue and traffic is Not dropped by any security service or rule.


Environment


  • Strata firewalls running PanOS 10.0.x or above
  • Prisma Access running dataplane 10.0
  • Traffic is subjected to SSL decryption with the security rule having at least 1 security profile.


Cause


The issue is caused by an issue in the content decoder processing of the PanOS which results in the corruption of the downloaded file.
 


Resolution


The issue is fixed by upgrading to the PanOS 10.0.10 / 10.0.9-h1 / 10.1.5 or 10.2.1 release.

Available workaround until the upgrade can be done:

  1. Disable SSL decryption for the traffic/user impacted.
  2. If that is not acceptable, Remove all the security profiles from the security rules the traffic matches.


Additional Information


  • The issue is usually observed when multiple files are downloaded simultaneously and the file size is larger than 100 MB.
  • Check the traffic/threat logs as well. If the download is blocked by a security policy or rule, this issue is Not applicable.

 


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000004O1vCAE&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language