<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Time out Oracle sessions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/time-out-oracle-sessions/m-p/162582#M52717</link>
    <description>&lt;P&gt;Oracle and firewalls in general, in my expereince, don't play that well together. &amp;nbsp;In our environment we had to extend the session&amp;nbsp;timeout in the app-id to a ridiculous number so that sessions wouldn't drop. &amp;nbsp;Alot of this seems to surroud the use of connection pooling where Oracle opens connections for use ahead of time to improve performance. &amp;nbsp;Firewalls will close these conntections (session timeout) if there is no interesting traffic (I think 6 packets in the session timeout value). &amp;nbsp;This means that clients may try to connect on ports that were previously closed by the firewall. &amp;nbsp;We trying setting up keepalives on the Oracle side of the house, but I was having issues getting any help from our developers in general at that time (over a year ago) as they managed the server settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would recommend as a troubleshooting step overriding the app-id session timeout for Oracle to like 8 hours and see if you still have the issue. &amp;nbsp;Just some food for thought.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Matt&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jun 2017 21:00:25 GMT</pubDate>
    <dc:creator>mlinsemier</dc:creator>
    <dc:date>2017-06-21T21:00:25Z</dc:date>
    <item>
      <title>Time out Oracle sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/time-out-oracle-sessions/m-p/162483#M52703</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have problems with time-outs in Oracle connections. We are seeing how the BBDD sends keep alives and in the FW is increased the number of packets when passing the keep-alive packet, but following one of these connections, in one of them we did not see increase the number of packets in the firewall, And the time to live of the session is not reset. We see how the server restarted its time to send a keep alive again. And we have some sessions that the firewall cuts by time-out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reviewing Release Notes, we've seen a bug that might be affecting us. This bug is solved in 7.1.6 PanOS:&lt;BR /&gt;PAN-64727: Fixed an issue where the firewall changed the sequence numbers of forwarded TCP keep-alive packets&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im not sure if this bus ia applying to us and causing this problem in 7.0.x. This problem will be solved in last panos in 7.0.x???&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 10:16:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/time-out-oracle-sessions/m-p/162483#M52703</guid>
      <dc:creator>Es_tecsupportsecurity</dc:creator>
      <dc:date>2017-06-21T10:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Time out Oracle sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/time-out-oracle-sessions/m-p/162542#M52710</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53726"&gt;@Es_tecsupportsecurity&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That specific bug number does not appear to be affecting 7.0.*, however the bug itself could have been given a seperate number. I did a quick scan through the release notes and didn't notice anything specific to keep-alive that seemed relavent to your issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would reach out to your SE or contact TAC and see if it was a bug that actually effects 7.0.* and if it is if there is even a plan to backport the fix to 7.0&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 16:08:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/time-out-oracle-sessions/m-p/162542#M52710</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-21T16:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: Time out Oracle sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/time-out-oracle-sessions/m-p/162582#M52717</link>
      <description>&lt;P&gt;Oracle and firewalls in general, in my expereince, don't play that well together. &amp;nbsp;In our environment we had to extend the session&amp;nbsp;timeout in the app-id to a ridiculous number so that sessions wouldn't drop. &amp;nbsp;Alot of this seems to surroud the use of connection pooling where Oracle opens connections for use ahead of time to improve performance. &amp;nbsp;Firewalls will close these conntections (session timeout) if there is no interesting traffic (I think 6 packets in the session timeout value). &amp;nbsp;This means that clients may try to connect on ports that were previously closed by the firewall. &amp;nbsp;We trying setting up keepalives on the Oracle side of the house, but I was having issues getting any help from our developers in general at that time (over a year ago) as they managed the server settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would recommend as a troubleshooting step overriding the app-id session timeout for Oracle to like 8 hours and see if you still have the issue. &amp;nbsp;Just some food for thought.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 21:00:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/time-out-oracle-sessions/m-p/162582#M52717</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2017-06-21T21:00:25Z</dc:date>
    </item>
  </channel>
</rss>

