Forward Segments Exceeding TCP Content Inspection Queue | Enable this option to forward TCP segments
and skip content inspection when the TCP content inspection queue
is full. The firewall can queue up to 64 segments while waiting
for the content engine. When the firewall forwards a segment and
skips content inspection due to a full content inspection queue,
it increments the following global counter: ctd_exceed_queue_limit Disable
this option to prevent the firewall from forwarding TCP segments
and skipping content inspection when the content inspection queue
is full. When you disable this option, the firewall drops any segments
that exceed the queue limit and increments the following global
counter: ctd_exceed_queue_limit_drop This
pair of global counters applies to both TCP and UDP packets. If,
after viewing the global counters, you decide to change the setting,
you can modify it from within your CLI using the following command: set
deviceconfig setting ctd tcp-bypass-exceed-queue
This option is enabled by default, but Palo
Alto Networks recommends that you disable this option for maximum
security. However, due to TCP retransmissions for dropped traffic,
disabling this option can result in performance degradation and loss
of functionality for some applications—particularly in high-volume traffic
environments.
|