Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootHard
A security engineer is troubleshooting a scenario where users are complaining about very slow application performance when accessing an internal web application. The Palo Alto Networks firewall is configured with Security policies that allow the traffic, and no threat logs are being generated for these sessions. However, the session browser on the firewall shows high 'pkt-proc-delay' values for the affected sessions. What does a high 'pkt-proc-delay' value typically indicate?
- AThe application server itself is experiencing performance issues.
- BThe firewall's CPU or dataplane resources are heavily utilized.
- CThe security policy is matching too many rules, causing processing overhead.
- DThe network latency between the client and the firewall is high.
Show answer & explanationAnswer & explanation
Correct answer: B. The firewall's CPU or dataplane resources are heavily utilized.
The 'pkt-proc-delay' field in the session browser specifically measures the time a packet spends being processed by the firewall's dataplane. High values indicate that the firewall itself is taking a long time to process packets, which is a strong indicator of resource exhaustion (CPU, session capacity, memory) on the firewall's dataplane, leading to performance bottlenecks.
Why the other options are wrong
- A. Application server performance issues would increase overall response times but wouldn't specifically manifest as high 'pkt-proc-delay' on the firewall itself.
- C. While a large rule base can add overhead, 'pkt-proc-delay' directly points to dataplane processing time, which is more about resource bottlenecks than just rule count.
- D. Network latency between client and firewall would increase RTT (Round Trip Time) but not directly 'pkt-proc-delay', which is firewall-internal processing.
Palo Alto pkt-proc-delay
The 'pkt-proc-delay' metric in the Palo Alto Networks firewall session browser indicates the time a packet spends being processed by the firewall's dataplane.
- High values suggest firewall resource exhaustion.
- Identifies bottlenecks within the firewall itself.
- Often points to CPU, session, or memory limits.
Memory trick: Packet Processing Delay: The 'Processor' is the 'Problem'.