TCP session timeout

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

TCP session timeout

L3 Networker

Hello Team,

 

Just a query - wanted to understand few things related to PA- sessions timeout.

 

We have a server -   which needs to connect to a specific port say 8xxx or 9xxx but unfortunately it requires connection to be established till more that 10 hours say 12 hours for example.

 

So how can i achieve this ?

 

1. can i change global setting of TCP session of 3600 to 43200 -12 hours , if yes that what impact will i be facing.

current scenario my MP and DP load is 3-6%

 

2. For that security policy - under service ports - 8xxx and 9xxx if i increase the TCP session timeout setting to 43200 -12 hours.

will it override the global settings which is applied for all sessions ?

 

Please guide or at least provide a specific document to justify to the customer.

 

 

 

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hello @Doyenadmin

 

thank you for the post.

 

1. Personally, I would start with changing it on application / service port level first instead of changing it globally for all sessions. Regarding impact changing this globally, it is hard to give estimate without knowing your customer traffic environment, however since firewall has to maintain sessions for prolog time, you could doble your DP utilization. Also you should watch for maximum session count and memory utilization.

 

2. This is correct understanding. Changing time out on service port level will override global setting: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/app-id/service-based-session-timeouts

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Hello @Doyenadmin

 

thank you for the post.

 

1. Personally, I would start with changing it on application / service port level first instead of changing it globally for all sessions. Regarding impact changing this globally, it is hard to give estimate without knowing your customer traffic environment, however since firewall has to maintain sessions for prolog time, you could doble your DP utilization. Also you should watch for maximum session count and memory utilization.

 

2. This is correct understanding. Changing time out on service port level will override global setting: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/app-id/service-based-session-timeouts

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Thanks alot @PavelK for confirming the same, appreciate your help.

  • 1 accepted solution
  • 2064 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!