<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Session timeout in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/session-timeout/m-p/49734#M36635</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;1. what is default session timeout for http traffic?&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;from my testing it will hit web-browsing application event though i create the policy use service instead of application.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Yes, irrespective what service you select Paloalto will still identify the application and in this case it is web-browsing. and the default timeouts for web-browsing are&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&amp;nbsp; Session timeout (second) : 30&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP timeout (second) : 3600&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP timeout (second): 30&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;"my question is what session timeout that firewall use? 30 or 3600 ? from my testing it use 30 but from the description session timeout will use if tcp session timeout and UDP timeout are not specified but why i see the timeout value 30 second"&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;TCP Web-browsing sessions will have a time out of 3600 seconds. You might see a timeout value of 30 seconds for these TCP sessions when the web-server sends a FIN due to inactivity of the user. So initially when you open a website and check the TCP sessions immediately on the firewall, you will observer the timeout as 3600 secs. After a few seconds of inactivity on the web-site the web-server can send a FIN and this point the TCP sessions timeout will change from 3600 to a value of 30 seconds. You might be looking at this behavior. You can also see a time out of 30secs if you close the browser in which case the web-browser (client) is sending the FIN this time.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 17 Sep 2012 18:07:38 GMT</pubDate>
    <dc:creator>sdurga</dc:creator>
    <dc:date>2012-09-17T18:07:38Z</dc:date>
    <item>
      <title>Session timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-timeout/m-p/49732#M36633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i want to ask about session timeout setting in palo alto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if we create policy to allow traffic from trust to untrust with service http (custom http port 80)&lt;/P&gt;&lt;P&gt;1. what is default session timeout for http traffic?&lt;/P&gt;&lt;P&gt;from my testing it will hit web-browsing application event though i create the policy use service instead of application.&lt;/P&gt;&lt;P&gt;2. is it a correct behavior ?&lt;/P&gt;&lt;P&gt;3. from web-browsing application i can see the 3 session timeout setting for this web-application&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session timeout (second) : 30&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP timeout (second) : 3600&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP timeout (second): 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then from help guide&lt;/P&gt;&lt;P&gt;timeouts : &lt;/P&gt;&lt;TABLE cellspacing="0" class="TW_TableWide" id="1482760" style="margin-bottom: 12pt;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD id="tc1482846" style="border-bottom-style: solid; border-bottom-width: 1pt; border-left-style: none; border-left-width: 1px; border-right-style: none; border-right-width: 1px; border-top-style: none; border-top-width: thin; border-color: Black; padding: pt;"&gt;&lt;P class="TB_TableBody"&gt;&lt;A name="1482846"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD id="tc1482848" style="border-bottom-style: solid; border-bottom-width: 1pt; border-left-style: none; border-left-width: 1px; border-right-style: none; border-right-width: 1px; border-top-style: none; border-top-width: thin; border-color: Black; padding: pt;"&gt;&lt;P class="TB_TableBody"&gt;&lt;A name="1482848"&gt;Enter the number of seconds before an idle application flow is terminated &lt;/A&gt;(range 0-604800). A zero indicates that the default timeout will be used. This value is used for protocols other than TCP and UDP in all cases and for TCP and UDP timeouts when the TCP timeout and UDP timeout are not specified.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD id="tc1482846" style="border-bottom-style: solid; border-bottom-width: 1pt; border-left-style: none; border-left-width: 1px; border-right-style: none; border-right-width: 1px; border-top-style: none; border-top-width: thin; border-color: Black; padding: pt;"&gt;&lt;/TD&gt;&lt;TD id="tc1482848" style="border-bottom-style: solid; border-bottom-width: 1pt; border-left-style: none; border-left-width: 1px; border-right-style: none; border-right-width: 1px; border-top-style: none; border-top-width: thin; border-color: Black; padding: pt;"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;my question is what session timeout that firewall use? 30 or 3600 ? from my testing it use 30 but from the description session timeout will use if tcp session timeout and UDP timeout are not specified but why i see the timeout value 30 second&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2012 15:49:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-timeout/m-p/49732#M36633</guid>
      <dc:creator>el</dc:creator>
      <dc:date>2012-09-17T15:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Session timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-timeout/m-p/49733#M36634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These documents will answer your question about the timeout values:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-2364"&gt;https://live.paloaltonetworks.com/docs/DOC-2364&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1581"&gt;https://live.paloaltonetworks.com/docs/DOC-1581&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2012 16:07:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-timeout/m-p/49733#M36634</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-09-17T16:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: Session timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/session-timeout/m-p/49734#M36635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;1. what is default session timeout for http traffic?&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;from my testing it will hit web-browsing application event though i create the policy use service instead of application.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Yes, irrespective what service you select Paloalto will still identify the application and in this case it is web-browsing. and the default timeouts for web-browsing are&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&amp;nbsp; Session timeout (second) : 30&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP timeout (second) : 3600&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP timeout (second): 30&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;"my question is what session timeout that firewall use? 30 or 3600 ? from my testing it use 30 but from the description session timeout will use if tcp session timeout and UDP timeout are not specified but why i see the timeout value 30 second"&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;TCP Web-browsing sessions will have a time out of 3600 seconds. You might see a timeout value of 30 seconds for these TCP sessions when the web-server sends a FIN due to inactivity of the user. So initially when you open a website and check the TCP sessions immediately on the firewall, you will observer the timeout as 3600 secs. After a few seconds of inactivity on the web-site the web-server can send a FIN and this point the TCP sessions timeout will change from 3600 to a value of 30 seconds. You might be looking at this behavior. You can also see a time out of 30secs if you close the browser in which case the web-browser (client) is sending the FIN this time.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2012 18:07:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/session-timeout/m-p/49734#M36635</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-17T18:07:38Z</dc:date>
    </item>
  </channel>
</rss>

