This is the maximum TTL in minutes, which
is the maximum time that any Authentication Portal session can remain
mapped (range is 1 to 1,440; default is 60). After this duration
elapses, PAN-OS removes the mapping and users must re-authenticate
even if the session is active. This timer prevents stale mappings
and overrides the Idle Timer value.
You should always set the expiration Timer higher
than the Idle Timer.
|