<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scheduler should cut off sessions immediately in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/scheduler-should-cut-off-sessions-immediately/m-p/7309#M5413</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;As per my understanding, a continuous session, that was previously initiated during the permit time should not block when the allowed schedule runs out. Until and unless, &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;if you enable "rematch sessions" and then commit the configuration, then only existing sessions would be &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rematched&lt;/SPAN&gt;&lt;/SPAN&gt; to policy (and blocked in this case if the schedule dictates that action).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;IMG __jive_id="11008" alt="Policy-rematch.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11008_Policy-rematch.JPG.jpg" style="width: 620px; height: 276px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;If "rematch session" is enabled in your firewall, then you can remove for the time being and test the result.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;I hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Jan 2014 14:54:40 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-01-15T14:54:40Z</dc:date>
    <item>
      <title>Scheduler should cut off sessions immediately</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scheduler-should-cut-off-sessions-immediately/m-p/7308#M5412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have set a schedule on some security policies, but at the moment the schedule should switch off the traffic it seems that live sessions are not immediately denied,&amp;nbsp; The scheduler only prohibits the creation of new sessions.&amp;nbsp; Is this true?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are on 5.0.4 witgh our PA500 box and I wonder if I can configure the scheduler to immediately cut off ALL the policy's traffic at the schedule's switch off moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for comments and advice on this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards Tor &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jan 2014 13:41:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scheduler-should-cut-off-sessions-immediately/m-p/7308#M5412</guid>
      <dc:creator>LCMember4427</dc:creator>
      <dc:date>2014-01-15T13:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduler should cut off sessions immediately</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scheduler-should-cut-off-sessions-immediately/m-p/7309#M5413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;As per my understanding, a continuous session, that was previously initiated during the permit time should not block when the allowed schedule runs out. Until and unless, &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;if you enable "rematch sessions" and then commit the configuration, then only existing sessions would be &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;rematched&lt;/SPAN&gt;&lt;/SPAN&gt; to policy (and blocked in this case if the schedule dictates that action).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;IMG __jive_id="11008" alt="Policy-rematch.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11008_Policy-rematch.JPG.jpg" style="width: 620px; height: 276px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;If "rematch session" is enabled in your firewall, then you can remove for the time being and test the result.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;I hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Jan 2014 14:54:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scheduler-should-cut-off-sessions-immediately/m-p/7309#M5413</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-15T14:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduler should cut off sessions immediately</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scheduler-should-cut-off-sessions-immediately/m-p/7310#M5414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response.&amp;nbsp; The Rematch Sessions was actually checked in my case, but despite that a lot of traffic is going on through the rule which is actually scheduled to switch off hours before.&amp;nbsp; However all these log entries are of 'Type' 'end'.&amp;nbsp; &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Does this mean that a user can continue using his Facebook session for hours after the policy allowing it is actually switched off by a schedule?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would the same 'negligence' of ongoing sessions apply if I create a deny rule scheduled the opposite way?&amp;nbsp; (I.e. that it starts to deny at the moment the daytime allow rule is switched off by a schedule).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If my PA box is not capable of enforcing schedules in an effective way I simply have to set a scheduled power switch on the distribution switches from the two firewall interfaces in question.&amp;nbsp; I never thought I would have to do that having a such expensive box and licenses as my PA equipment.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards Tor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jan 2014 08:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scheduler-should-cut-off-sessions-immediately/m-p/7310#M5414</guid>
      <dc:creator>LCMember4427</dc:creator>
      <dc:date>2014-01-16T08:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduler should cut off sessions immediately</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/scheduler-should-cut-off-sessions-immediately/m-p/7311#M5415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;In the case of Deny rules, the traffic is denied immediately when it matches the criterion defined in the security policy so the start and end of the session should be the same. As such you'd be fine, just logging at the start of a Deny policy. You'd not have to wait for the FIN/ &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;FIN ACK&lt;/SPAN&gt;&lt;/SPAN&gt; to determine the end of the session. So, for &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;a deny rule&lt;/SPAN&gt; &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;(I.e. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;that&lt;/SPAN&gt;&lt;/SPAN&gt; it starts to deny at the moment the daytime allow rule is switched off by a schedule) will not be able to close/deny for an ongoing session, &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;untill&lt;/SPAN&gt;&lt;/SPAN&gt; and unless you are applying a "commit force" command or enforcing "session rematch".&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;So, as per my understanding the scheduler policy will be applied to a newly created session, nor for a running session through the PAN firewall. &lt;/SPAN&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;As per my understanding, most of the leading vendor firewall is working like this. &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;( &lt;/SPAN&gt;Example- PAN, Juniper SRX).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;If you have any further questions or inquiries, please open a case with PAN support, we will help you to fulfill your requirements.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 1.5em; color: #3b3b3b; font-size: 10pt; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;&lt;EM&gt;Please mark as correct answer or helpful if appropriate.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jan 2014 08:41:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/scheduler-should-cut-off-sessions-immediately/m-p/7311#M5415</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-16T08:41:38Z</dc:date>
    </item>
  </channel>
</rss>

