<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Discard UDP from Paloalto Session TImeout in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/discard-udp-from-paloalto-session-timeout/m-p/526870#M108885</link>
    <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you for your kind explanation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The cause that NGFW is not creating a new UDP session is still under analysis.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Could you please explain more what are the benefits of setting up Discard UDP timeout?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Jan 2023 00:21:53 GMT</pubDate>
    <dc:creator>JoHyeonJae</dc:creator>
    <dc:date>2023-01-13T00:21:53Z</dc:date>
    <item>
      <title>Discard UDP from Paloalto Session TImeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/discard-udp-from-paloalto-session-timeout/m-p/526730#M108851</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-01-12 at 9.40.17 AM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/46945iDAEA1DA57E468203/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-01-12 at 9.40.17 AM.png" alt="Screenshot 2023-01-12 at 9.40.17 AM.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Hello all,&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Recently, customers are experiencing a phenomenon that Syslog traffic coming into the same source port remains in the Discarded Deny Session.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;As a result of my checking, it was confirmed that it occurred while being constantly refreshed due to Discard UDP Timeout in Paloalto Session Timeout setting.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#f3723c"&gt;&lt;SPAN&gt;&lt;U&gt;Discard UDP :&amp;nbsp;&lt;/U&gt;&lt;/SPAN&gt;&lt;/FONT&gt;Maximum length of time (in seconds) that a UDP session remains open after PAN-OS denies the session based on Security policy rules configured on the firewall (range is 1 to 15,999,999; default is 60).&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Does anyone know why Discard UDP values are needed?&lt;BR /&gt;&lt;BR /&gt;Thanks and regards,&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 00:53:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/discard-udp-from-paloalto-session-timeout/m-p/526730#M108851</guid>
      <dc:creator>JoHyeonJae</dc:creator>
      <dc:date>2023-01-12T00:53:06Z</dc:date>
    </item>
    <item>
      <title>Re: Discard UDP from Paloalto Session TImeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/discard-udp-from-paloalto-session-timeout/m-p/526823#M108876</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208779"&gt;@JoHyeonJae&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This document is a good reference -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/session-settings-and-timeouts/configure-session-timeouts" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/session-settings-and-timeouts/configure-session-timeouts&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Note box indicates that they are optimal values that can be modified "according to your network needs."&amp;nbsp; The UDP protocol has no mechanism to end a session like TCP.&amp;nbsp; Therefore, the NGFW does not know when a session ends based upon packet inspection.&amp;nbsp; It relies on the session aging out.&amp;nbsp; This is why the most common Session End Reason for UDP under Monitor &amp;gt; Logs &amp;gt; Traffic is aged-out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Notice also that the doc says you can adjust the application-specific timers.&amp;nbsp; If your traffic is identified as "syslog," it has a UDP timeout of 30 seconds that overrides the global timeout.&amp;nbsp; If you are positive it is a timeout issue, you can increase the App-ID timeout.&amp;nbsp; Increasing the global timeouts will result in more active sessions on the NGFW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a great article on session states -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVECA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVECA0&lt;/A&gt;.&amp;nbsp; Typically discard identifies a security policy or threat detection drop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am curious why the NGFW does not create a new UDP session if the old session timed out.&amp;nbsp; As mentioned earlier, UDP is not like TCP with session setup and teardown.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jan 2023 18:06:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/discard-udp-from-paloalto-session-timeout/m-p/526823#M108876</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-01-12T18:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: Discard UDP from Paloalto Session TImeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/discard-udp-from-paloalto-session-timeout/m-p/526870#M108885</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you for your kind explanation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The cause that NGFW is not creating a new UDP session is still under analysis.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Could you please explain more what are the benefits of setting up Discard UDP timeout?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 00:21:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/discard-udp-from-paloalto-session-timeout/m-p/526870#M108885</guid>
      <dc:creator>JoHyeonJae</dc:creator>
      <dc:date>2023-01-13T00:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Discard UDP from Paloalto Session TImeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/discard-udp-from-paloalto-session-timeout/m-p/526872#M108886</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/208779"&gt;@JoHyeonJae&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The main value of adjusting the protocol timeouts is so that &lt;EM&gt;return&lt;/EM&gt; traffic will be allowed through the NGFW based upon the session.&amp;nbsp; Most syslog traffic is unidirectional.&amp;nbsp; So, it should not be needed.&amp;nbsp; Are you sure the syslog drops are caused by the UDP timeout value?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 01:00:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/discard-udp-from-paloalto-session-timeout/m-p/526872#M108886</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-01-13T01:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Discard UDP from Paloalto Session TImeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/discard-udp-from-paloalto-session-timeout/m-p/526873#M108887</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Yes, a Syslog failure has occurred and I have cleared all the discarded sessions, and syslog Issue has been resolved.&lt;BR /&gt;&lt;BR /&gt;This is the reason why the customer asked me why Discard UDP is needed.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 01:09:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/discard-udp-from-paloalto-session-timeout/m-p/526873#M108887</guid>
      <dc:creator>JoHyeonJae</dc:creator>
      <dc:date>2023-01-13T01:09:09Z</dc:date>
    </item>
  </channel>
</rss>

