<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP Timeouts ... Again in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31587#M23091</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so I did the debug trace.. Not as easy as a tcpdump but whatever. In the Drop trace I see PA dropping keep alives. See attached. Any ideas ? Is PA dropping keep alives which is why I am getting idle sessions terminating ? If so, where can I change this ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Mar 2011 15:40:06 GMT</pubDate>
    <dc:creator>jickfoo</dc:creator>
    <dc:date>2011-03-17T15:40:06Z</dc:date>
    <item>
      <title>TCP Timeouts ... Again</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31586#M23090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a bunch of connection, 12 to be exact. From a webserver to a Oracle DB Server. They timeout every 2 hours.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They pass through a Cisco ASA and a PA 4020. I've created and override rule with a custom app with no timeout. (see attached)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm in the position where I need to prove this is not the Palo Alto killing the connection. I'm sure it's not closing naturally. Something is killing the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I prove this on the PA? I know when the connections are going to die. I'm going to do a packet capture with the debug flow commands. Any hints on what to look for ? Will I see TCP RSTs or Fins sourced from the PA ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Justin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 13:34:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31586#M23090</guid>
      <dc:creator>jickfoo</dc:creator>
      <dc:date>2011-03-17T13:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Timeouts ... Again</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31587#M23091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so I did the debug trace.. Not as easy as a tcpdump but whatever. In the Drop trace I see PA dropping keep alives. See attached. Any ideas ? Is PA dropping keep alives which is why I am getting idle sessions terminating ? If so, where can I change this ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 15:40:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31587#M23091</guid>
      <dc:creator>jickfoo</dc:creator>
      <dc:date>2011-03-17T15:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Timeouts ... Again</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31588#M23092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two remarks:&lt;/P&gt;&lt;P&gt;- From the first picture you send it seems that you did not set the timers. This means that the default timers will apply. If you want to set your own timers please configure them in the application. If you want the session to not time out set the timeout to zero (0).&lt;/P&gt;&lt;P&gt;- If you want to prove the Palo Alto Networks is not the problem then if the session is killed see if the session is still in the session table of the Palo Alto Networks. This might prove easily (before taking any captures) that the session is still active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 15:57:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31588#M23092</guid>
      <dc:creator>mderksen</dc:creator>
      <dc:date>2011-03-17T15:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Timeouts ... Again</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31589#M23093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I think we had this conversation before. Someone told me that the greyed out timers is an indication that they are off. If I set them to 0 it goes back to what you see there. I can set them to 2 weeks and see if it bypasses the 2 hour timeout.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I look at the session tables ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did run the captures already. Any thoughts as to why there was data in the drop capture ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 16:04:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31589#M23093</guid>
      <dc:creator>jhickey</dc:creator>
      <dc:date>2011-03-17T16:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Timeouts ... Again</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31590#M23094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can look at the session table with the command from the CLI or (if you have) via the option in the monitor and use the session browser.&lt;/P&gt;&lt;P&gt;From the CLI use the command 'show session all' and use the filter command to make it useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 16:11:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31590#M23094</guid>
      <dc:creator>mderksen</dc:creator>
      <dc:date>2011-03-17T16:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Timeouts ... Again</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31591#M23095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;k thanks.. I have a case open and I'll report back what happens. I thought we had success last night as I set the settings from they greyed out zero to the max 604800 and there was no timeout .. until 6 hours later. (not the usual 2 hours) BUT to complicate things there was also a bit of a network outage last night around the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set the timers back to the greyed out zero and will find out in about 40 minutes if the sessions crash again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To me there should be an easier way to see if a session was closed due to the firewall thinking it is idle. It should be in the logs. (Session Close: Reason: FW TCP Timeout)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Mar 2011 13:10:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31591#M23095</guid>
      <dc:creator>jhickey</dc:creator>
      <dc:date>2011-03-18T13:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Timeouts ... Again</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31592#M23096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The sessions did get taken down again. I'm fairly certain the Palo Alto Firewall took it down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set the timeout to 604799 and restarted the services. It's been 6 hours now and the connection is solid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, in conclusion, 0 = 2 hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still think there should be a way to prevent the PA from ever tearing connections down due to 'idle timers'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I made the request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Justin &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Mar 2011 19:50:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31592#M23096</guid>
      <dc:creator>jhickey</dc:creator>
      <dc:date>2011-03-18T19:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Timeouts ... Again</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31593#M23097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We had a similar problems recently, after a call with Support it was determined that we modified some tcp timeout timers. The below commands resovled our issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color: red;"&gt;PAN&amp;gt;configure &lt;BR /&gt; PAN#set deviceconfig setting tcp drop-out-of-wnd no &lt;BR /&gt; PAN#set deviceconfig setting tcp bypass-exceed-oo-queue yes &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 9pt; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; color: red;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 May 2012 20:33:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-timeouts-again/m-p/31593#M23097</guid>
      <dc:creator>opiedrah</dc:creator>
      <dc:date>2012-05-03T20:33:39Z</dc:date>
    </item>
  </channel>
</rss>

