<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Web filtering only license/Idle time outs. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/web-filtering-only-license-idle-time-outs/m-p/35346#M25964</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have 2 PA-500 inline for web filtering only. We are having an idle timeout problem with none url traffic and have determined the issue is with the PA's. I have seen posts on this issue that relate to firewall functionality that I am not using. Does anyone know where/how to address this issue on the PA's? Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Sep 2011 13:57:02 GMT</pubDate>
    <dc:creator>rthimble</dc:creator>
    <dc:date>2011-09-22T13:57:02Z</dc:date>
    <item>
      <title>Web filtering only license/Idle time outs.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-filtering-only-license-idle-time-outs/m-p/35346#M25964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have 2 PA-500 inline for web filtering only. We are having an idle timeout problem with none url traffic and have determined the issue is with the PA's. I have seen posts on this issue that relate to firewall functionality that I am not using. Does anyone know where/how to address this issue on the PA's? Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2011 13:57:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-filtering-only-license-idle-time-outs/m-p/35346#M25964</guid>
      <dc:creator>rthimble</dc:creator>
      <dc:date>2011-09-22T13:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: Web filtering only license/Idle time outs.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-filtering-only-license-idle-time-outs/m-p/35347#M25965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you tell us more your observation and your config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jones &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2011 14:38:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-filtering-only-license-idle-time-outs/m-p/35347#M25965</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-09-22T14:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: Web filtering only license/Idle time outs.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-filtering-only-license-idle-time-outs/m-p/35348#M25966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have dual PA-500's in HA mode, inline for all traffic destined to the Internet. The PA's are in front of our Firewalls which are Checkpoints. The only rule sets on the PA's are for url filtering, anti virus, anti spam. The PA's are not in full production as of yet. There are 3 active url rules effecting a select group for testing. The activity that is timeing out is none url traffic destined to a hosting service via VPN. We have eliminated the vpn device and the firewall by working backwards and testing on each segment. That leaves the PA's. From what I have read the timeouts can be addressed in the rule base by protocol or application. My question is how do I address the idle timeout in this scenario?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2011 18:32:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-filtering-only-license-idle-time-outs/m-p/35348#M25966</guid>
      <dc:creator>rthimble</dc:creator>
      <dc:date>2011-09-22T18:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: Web filtering only license/Idle time outs.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-filtering-only-license-idle-time-outs/m-p/35349#M25967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Rick.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have two options to change the idle timeout. Before changing the value you can run "show session info" to understand the current value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Change the global TCP and UDP timeout by CLI:&lt;/P&gt;&lt;P&gt;Configure&lt;/P&gt;&lt;P&gt;set deviceconfig setting session timeout-tcp/timeout-udp &amp;lt;value&amp;gt;&lt;/P&gt;&lt;P&gt;commit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Change the per-application value. You need to know what applications we have identified the traffic as through the traffic log before applying the change:&lt;/P&gt;&lt;P&gt;go to object -&amp;gt; application -&amp;gt; click on the application and change the timeout value&lt;/P&gt;&lt;P&gt;commit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jones&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Sep 2011 06:36:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-filtering-only-license-idle-time-outs/m-p/35349#M25967</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-09-23T06:36:40Z</dc:date>
    </item>
  </channel>
</rss>

