This is the maximum TTL in minutes, which is the
maximum time that any Authentication Portal session can remain
mapped (range is 1 to 1,440; default is 60). After this duration
elapses, PAN-OS removes the mapping and users must re-authenticate
even if the session is active. This timer prevents stale mappings
and overrides the Idle Timer value.
You should always set the expiration
Timer higher than the Idle
Timer.
|