Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

How to identify long live session(s) ?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

How to identify long live session(s) ?

L4 Transporter

Hello,

 

I am trying to identify those long live sessions on my firewall,  I mean those session(s) that never ended for weeks at a time.

 

This is what I found out so far.

 

1.  I can't export the whole session log to perform offline analysis,

2,  I did not find anything related to session start time as filter under show session all filter.

3.  ACC will only record when a session is closed, I don't believe ACC will show that session data (session #, packets used, bytes used) until the session is ended.

 

Any suggestion?  

 

Thanks in advanced,

 

6 REPLIES 6

Cyber Elite
Cyber Elite

I think session table shows up to 1024 sessions at once.

If you don't have too many sessions then you could export from cli.

show session all start-at 1

show session all start-at 1025

etc

 

By the way ACC data comes directly from dataplane and it does not matter if sec policy has "log at session start" and "log at session end" checked - ACC still shows everything. ACC is not real time - it has 15 min delay.

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Raido,

 

I thought about that, but the firewall have about 1 million active sessions  +/-  250k at any given time.    I was trying to look up how does ACC work, do you have a link to a techdoc?   For sure,  I am seeing long live session does not show up on ACC until the session is closed.

 

-E

How about using custom report?

If you select 'traffic log (detailed log, not summary database), you can use one column named 'elapsed time (sec)'.

 

In this case all security policies should have "log at session start" that is not default.

It is nice option but writes a lot more log and log retention period is shorter.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

I will need to try the custom report.   Thanks for the tips.

L1 Bithead

How about using the XML API calls on the firewall and filtering by min-age?

 

604800 seconds is a week.


/api/?type=op&cmd=<show><session><all><filter><min-age>604800</min-age></filter></all></session></show>

  • 3689 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!