|
Forward Segments Exceeding TCP Content Inspection Queue
|
Enable this option to forward TCP segments and skip content
inspection when the TCP content inspection queue is full. The
firewall can queue up to 64 segments while waiting for the content
engine. When the firewall forwards a segment and skips content
inspection due to a full content inspection queue, it increments the
following global counter:
ctd_exceed_queue_limit
Disable this option to prevent the firewall from forwarding TCP
segments and skipping content inspection when the content inspection
queue is full. When you disable this option, the firewall drops any
segments that exceed the queue limit and increments the following
global counter:
ctd_exceed_queue_limit_drop
This pair of global counters applies to both TCP and UDP packets. If,
after viewing the global counters, you decide to change the setting,
you can modify it from within your CLI using the following
command:
set
deviceconfig setting ctd tcp-bypass-exceed-queue
This option is enabled by default, but Palo Alto Networks
recommends that you disable this option for maximum security.
However, due to TCP retransmissions for dropped traffic,
disabling this option can result in performance degradation and
loss of functionality for some applications—particularly in
high-volume traffic environments.
|