Linux and TCP keepalive

Reply
Alex_Samad
L4 Transporter

Linux and TCP keepalive

Hi

 

Is there some reason that PA have a 1 hour keepalive value, where linux has a 2 hour timeout value.

 

Whats considered best practices ... reset the PA to 2 hours or bring down the linux keepalive value to say 1800

 

A

BPry
Cyber Elite

@Alex_Samad,

Are you having an issue with the firewall being set to 60 minutes for the timeout instead of 120 like on linux? The firewall closes things a bit earlier to keep the session count down on the firewalls, and 60 minutes was tested and verified to cause a very small amount of issues. 

I'm guessing that this would be more of an internal application issue; and if it is I would recommend making a custom app-id with a higher timeout value. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!