set up TCP ports timeout

cancel
Showing results for 
Search instead for 
Did you mean: 

set up TCP ports timeout

L3 Networker

Hello Community,

 

I need to know if it is possible?

 

 change the timeout for the following TCP ports to 4 hours (14400 seconds)

TCP 1521
TCP 2101
TCP 1601-1630
TCP 2101
TCP 18400-18430

 

Best Regards

Andres Padilla

Best Regards
3 REPLIES 3

L5 Sessionator

You can change the 'TCP timeout' option on the aplication which is recognised for that traffic. Or even better; make app override for that traffic and change the setting on this new app.

 

 

Community Team Member

Hi @Apadilla,

 

You can change the TCP timeout for an application, but not for the services.
For the services, there is no option to change the timeout.  By default it will use global timeout setting.

That being said, it should be possible to achieve your objective by using a custom application together with application override.

 

  1. Create the Custom Application:
    Leaving the defaults set to none on the advanced tab.  Here you can also adjust the timeout setting.
  2. Create the Service Port.
  3. Create the Policy for Application Override.
    Policies > Application Override.
    In here define the source and destination traffic. then map your port and the custom application.
    Under the Protocol/Application tab, set the port number and your custom app that you created in step 1
  4. Create the Security Policy.
    Define source and destination as specific as possible. Map the new service you defined in Step 2, and the custom application you created in Step 1.


Cheers !

-Kim.

 

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Don't forget to hit that Like button if a post is helpful to you!

L6 Presenter

Morning All,

 

Agreed with all comments. Custom APP with Application Override Policy is the way to go. Below detailed link on how to get this done:

 

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Create-an-Application-Override-Po...

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!