Is it possible to configure PA to send a reset(rst) packet when a session timeout occurs?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Is it possible to configure PA to send a reset(rst) packet when a session timeout occurs?

L0 Member

Hello.

I'm running a PA-1420 device.
The PAN-OS version is 11.0.3-h12.

Is it possible to configure the PA to send RST packets to both sides when a TCP session times out due to aged-out?
I read in a previous post that this wasn't possible on the PA, but I'm wondering if this is still the case.
(https://live.paloaltonetworks.com/t5/general-topics/pa-sends-a-reset-rst-when-tcp-session-is-timeout...)

Thank you.

2 REPLIES 2

Cyber Elite
Cyber Elite

@SoongNyeongKim,

As far as I'm aware, this is still not possible upon session timeout. PAN simply closes the session for aged-out traffic and that can't be modified from a behavior standpoint. 

Community Team Member

Hi @SoongNyeongKim ,

 

That being said, because this was brought up before I think it's would be a good candidate for a feature request.

 

 

For new features or product enhancements, the most effective way is to go through your dedicated Palo Alto Networks account team.

 

  • Contact Your Sales Engineer (SE): Your SE is the primary point of contact for submitting feature requests. They have direct access to the product management team and can formally submit your request into the internal system.

  • Provide Details: When you contact your SE, be prepared to provide a detailed use case. Explain why the feature is important and the business problem it would solve. This helps the product team understand the value and prioritize the request.

  • Voting on Existing Requests: If a similar feature has already been requested, your SE can add a "vote" on your behalf. This is crucial because the number of votes a feature receives from customers directly influences its priority and can expedite its development.

This process ensures your feedback is formally tracked and considered by the company's product development team. 
You can also ask users here to add their vote to it once you get a FR#.

 

Kind regards,

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 485 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!