Palo Alto 10.0.6 5220 and 'show session all filter min-age'

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Palo Alto 10.0.6 5220 and 'show session all filter min-age'

L2 Linker

Hello All,

 

Just wondering if 'show session all filter min-age 4000000' displays relevant information. We have around 3200 sessions in session table at average, but when I am trying to look for long-lived or even stuck(?) connections number using command above, it shows me around 200 connections. But if I take one of those 'old' ones number and view it via 'show session id X' - it will show that actual start date of this connection is... today.

 

Is there a discrepancy somewhere or am I missing something?

 

We are checking some weird issues and idea was that one of the sessions might be just stuck in a session table, causing appliance to consider that as a reuse and drop underlying traffic.

 

Thanks!

1 REPLY 1

L7 Applicator

IF I am hearing you correctly, there appears to be an "old" session, but when you go to get the details about it, it shows as still a current connection?

LIVEcommunity team member
Stay Secure,
Joe
Don't forget to Like items if a post is helpful to you!
  • 1840 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!