- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
09-19-2022 08:29 AM
Hello Team,
Just a query - wanted to understand few things related to PA- sessions timeout.
We have a server - which needs to connect to a specific port say 8xxx or 9xxx but unfortunately it requires connection to be established till more that 10 hours say 12 hours for example.
So how can i achieve this ?
1. can i change global setting of TCP session of 3600 to 43200 -12 hours , if yes that what impact will i be facing.
current scenario my MP and DP load is 3-6%
2. For that security policy - under service ports - 8xxx and 9xxx if i increase the TCP session timeout setting to 43200 -12 hours.
will it override the global settings which is applied for all sessions ?
Please guide or at least provide a specific document to justify to the customer.
09-21-2022 02:45 PM
Hello @Doyenadmin
thank you for the post.
1. Personally, I would start with changing it on application / service port level first instead of changing it globally for all sessions. Regarding impact changing this globally, it is hard to give estimate without knowing your customer traffic environment, however since firewall has to maintain sessions for prolog time, you could doble your DP utilization. Also you should watch for maximum session count and memory utilization.
2. This is correct understanding. Changing time out on service port level will override global setting: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/app-id/service-based-session-timeouts
Kind Regards
Pavel
09-21-2022 02:45 PM
Hello @Doyenadmin
thank you for the post.
1. Personally, I would start with changing it on application / service port level first instead of changing it globally for all sessions. Regarding impact changing this globally, it is hard to give estimate without knowing your customer traffic environment, however since firewall has to maintain sessions for prolog time, you could doble your DP utilization. Also you should watch for maximum session count and memory utilization.
2. This is correct understanding. Changing time out on service port level will override global setting: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/app-id/service-based-session-timeouts
Kind Regards
Pavel
09-21-2022 09:26 PM
Thanks alot @PavelK for confirming the same, appreciate your help.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!