<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TCP session timeout in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/tcp-session-timeout/m-p/515289#M399</link>
    <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just a query - wanted to understand few things related to PA- sessions timeout.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a server -&amp;nbsp; &amp;nbsp;which needs to connect to a specific port say 8xxx or 9xxx but unfortunately it requires connection to be established till more that 10 hours say 12 hours for example.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So how can i achieve this ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. can i change global setting of TCP session of 3600 to&amp;nbsp;43200 -12 hours , if yes that what impact will i be facing.&lt;/P&gt;
&lt;P&gt;current scenario my MP and DP load is 3-6%&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. For that security policy - under service ports - 8xxx and 9xxx if i increase the TCP session timeout setting to&amp;nbsp;43200 -12 hours.&lt;/P&gt;
&lt;P&gt;will it override the global settings which is applied for all sessions ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please guide or at least provide a specific document to justify to the customer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Sep 2022 15:29:52 GMT</pubDate>
    <dc:creator>Doyenadmin</dc:creator>
    <dc:date>2022-09-19T15:29:52Z</dc:date>
    <item>
      <title>TCP session timeout</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/tcp-session-timeout/m-p/515289#M399</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just a query - wanted to understand few things related to PA- sessions timeout.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a server -&amp;nbsp; &amp;nbsp;which needs to connect to a specific port say 8xxx or 9xxx but unfortunately it requires connection to be established till more that 10 hours say 12 hours for example.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So how can i achieve this ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. can i change global setting of TCP session of 3600 to&amp;nbsp;43200 -12 hours , if yes that what impact will i be facing.&lt;/P&gt;
&lt;P&gt;current scenario my MP and DP load is 3-6%&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. For that security policy - under service ports - 8xxx and 9xxx if i increase the TCP session timeout setting to&amp;nbsp;43200 -12 hours.&lt;/P&gt;
&lt;P&gt;will it override the global settings which is applied for all sessions ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please guide or at least provide a specific document to justify to the customer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 15:29:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/tcp-session-timeout/m-p/515289#M399</guid>
      <dc:creator>Doyenadmin</dc:creator>
      <dc:date>2022-09-19T15:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: TCP session timeout</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/tcp-session-timeout/m-p/515649#M405</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227096"&gt;@Doyenadmin&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for the post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Personally, I would start with changing it on application / service port level first instead of changing it globally for all sessions. Regarding impact changing this globally, it is hard to give estimate without knowing your customer traffic environment, however since firewall has to maintain sessions for prolog time, you could doble your DP utilization. Also you should watch for maximum session count and memory utilization.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. This is correct understanding. Changing time out on service port level will override global setting:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/app-id/service-based-session-timeouts" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/app-id/service-based-session-timeouts&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 21:45:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/tcp-session-timeout/m-p/515649#M405</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-09-21T21:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: TCP session timeout</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/tcp-session-timeout/m-p/515671#M406</link>
      <description>&lt;P&gt;Thanks alot&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;for confirming the same, appreciate your help.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 04:26:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/tcp-session-timeout/m-p/515671#M406</guid>
      <dc:creator>Doyenadmin</dc:creator>
      <dc:date>2022-09-22T04:26:23Z</dc:date>
    </item>
  </channel>
</rss>

