<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New Sessions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/new-sessions/m-p/44591#M32726</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Fernando,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my understanding, until all 5 parameters for tuple values &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Src&lt;/SPAN&gt; IP, &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Dst&lt;/SPAN&gt; IP, Src-port, &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Dst&lt;/SPAN&gt;-port, Protocol) are not same, the firewall will create a new session. For example, the firewall will create a different session for packet initiated&amp;nbsp; from the same source IP to destination IP &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;same protocol) with &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Src&lt;/SPAN&gt; port 1021, 1022, 1023 etc. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the firewall is again initiating a connection from &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;10.50.213.22 port 1020 -----&amp;gt; 10.65.22.15 port 515&lt;/SPAN&gt;, and old session is still active, I hope the FW will identify as a duplicate flow and drop it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;But &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;i&lt;/SPAN&gt; have read on a TCP RFC &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;not sure the RFC number&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;:&lt;/SPAN&gt;-RFC: 793, RFC: 1180 RFC: 1323)&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; ,&lt;/SPAN&gt; said that, if all 65535 source ports exhausted on a system, it can consider the "&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;time-stamp&lt;/SPAN&gt;" of the TCP SYN to identify/differentiate a new session with all 5 matching tuple parameters.&lt;/EM&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Mar 2014 22:15:23 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-03-13T22:15:23Z</dc:date>
    <item>
      <title>New Sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-sessions/m-p/44590#M32725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question, what happen when the firewall have a active session and need create a same session but the old session is active?, for example, the firewall have a following session&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.50.213.22 port 1020 -----&amp;gt; 10.65.22.15 port 515&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this session is active but the server still sending connections for example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.50.213.22 port 1021 -----&amp;gt; 10.65.22.15 port 515&lt;/P&gt;&lt;P&gt;10.50.213.22 port 1022 -----&amp;gt; 10.65.22.15 port 515&lt;/P&gt;&lt;P&gt;10.50.213.22 port 1023 -----&amp;gt; 10.65.22.15 port 515&lt;/P&gt;&lt;P&gt;10.50.213.22 port 1024 -----&amp;gt; 10.65.22.15 port 515&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but the next connection is again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.50.213.22 port 1020 -----&amp;gt; 10.65.22.15 port 515&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the firewall has an old active session, the question is what happen with the new session?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you help me with this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Mar 2014 20:09:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-sessions/m-p/44590#M32725</guid>
      <dc:creator>JosueFernando</dc:creator>
      <dc:date>2014-03-13T20:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: New Sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-sessions/m-p/44591#M32726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Fernando,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my understanding, until all 5 parameters for tuple values &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Src&lt;/SPAN&gt; IP, &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Dst&lt;/SPAN&gt; IP, Src-port, &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Dst&lt;/SPAN&gt;-port, Protocol) are not same, the firewall will create a new session. For example, the firewall will create a different session for packet initiated&amp;nbsp; from the same source IP to destination IP &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;same protocol) with &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Src&lt;/SPAN&gt; port 1021, 1022, 1023 etc. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the firewall is again initiating a connection from &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;10.50.213.22 port 1020 -----&amp;gt; 10.65.22.15 port 515&lt;/SPAN&gt;, and old session is still active, I hope the FW will identify as a duplicate flow and drop it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;But &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;i&lt;/SPAN&gt; have read on a TCP RFC &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;not sure the RFC number&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;:&lt;/SPAN&gt;-RFC: 793, RFC: 1180 RFC: 1323)&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; ,&lt;/SPAN&gt; said that, if all 65535 source ports exhausted on a system, it can consider the "&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;time-stamp&lt;/SPAN&gt;" of the TCP SYN to identify/differentiate a new session with all 5 matching tuple parameters.&lt;/EM&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Mar 2014 22:15:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-sessions/m-p/44591#M32726</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-03-13T22:15:23Z</dc:date>
    </item>
  </channel>
</rss>

