Configure Session Settings (PAN-OS)
Focus
Focus
Next-Generation Firewall

Configure Session Settings (PAN-OS)

Table of Contents


Configure Session Settings (PAN-OS)

Procedure for configuring session settings in PAN-OS and Panorama.
  1. Change the session settings.
    Select DeviceSetupSession and edit the Session Settings.
  2. Specify whether to apply newly configured Security policy rules to sessions that are in progress.
    Select Rematch all sessions on config policy change to apply newly configured Security policy rules to sessions that are already in progress. This capability is enabled by default. If you clear this check box, any policy rule changes you make apply only to sessions initiated after you commit the policy change.
    For example, if a Telnet session started while an associated policy rule was configured that allowed Telnet, and you subsequently committed a policy change to deny Telnet, the firewall applies the revised policy to the current session and blocks it.
  3. Configure IPv6 settings.
    • ICMPv6 Token Bucket Size—Default: 100 tokens. See the section ICMPv6 Rate Limiting.
    • ICMPv6 Error Packet Rate (per sec)—Default: 100. See the section ICMPv6 Rate Limiting.
    • Enable IPv6 Firewalling—Enables firewall capabilities for IPv6. All IPv6-based configurations are ignored if IPv6 is not enabled. Even if IPv6 is enabled for an interface, the IPv6 Firewalling setting must also be enabled for IPv6 to function.
  4. Enable jumbo frames and set the MTU.
    1. Select Enable Jumbo Frame to enable jumbo frame support on Ethernet interfaces. Jumbo frames have a maximum transmission unit (MTU) of 9,216 bytes and are available on certain models.
    2. Set the Global MTU, depending on whether or not you enabled jumbo frames:
      • If you did not enable jumbo frames, the Global MTU defaults to 1,500 bytes; the range is 576 to 1,500 bytes.
      • If you enabled jumbo frames, the Global MTU defaults to 9,192 bytes; the range is 9,192 to 9,216 bytes.
        On some firewall models (such as the PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls), Jumbo Frames can take up to five times more memory compared to normal packets and can reduce the number of available packet-buffers to just 20% of the packet buffer size that was available when Jumbo Frames were disabled. This reduces the queue sizes dedicated for out of order, application identification, and other such packet processing tasks. On the PA-7000 Series, PA-5200 Series, and PA-3200 Series firewalls, if you enable the jumbo frame global MTU configuration and reboot your firewall, packet buffers are then redistributed to process jumbo frames more efficiently.
        The following table indicates what percentage of the packet buffer size is available when Jumbo Frames are enabled (compared to the packet buffer size when Jumbo Frames are disabled).
        Packet Buffer Size (# of Packets)
        NGFW ModelJumbo Frames DisabledJumbo Frames Enabled
        PA-7000100%20%
        PA-5200100%20%
        PA-3200100%20%
        PA-5450100%100%
        PA-5400f100%80%
        PA-3400100%100%
      If you enable jumbo frames and you have interfaces where the MTU is not specifically configured, those interfaces will automatically inherit the jumbo frame size. Therefore, before you enable jumbo frames, if you have any interface that you do not want to have jumbo frames, you must set the MTU for that interface to 1500 bytes or another value.
      If you import (DeviceSetupOperationsImport) and load a configuration that has Jumbo Frame enabled, and then commit to a firewall that does not already have Jumbo Frame enabled, the Enable Jumbo Frame setting is not committed to the configuration. You should first Enable Jumbo Frame, reboot, and then import, load and commit the configuration.
  5. Tune NAT session settings.
    • NAT64 IPv6 Minimum Network MTU—Sets the global MTU for IPv6 translated traffic. The default of 1,280 bytes is based on the standard minimum MTU for IPv6 traffic.
    • NAT Oversubscription Rate—If NAT is configured to be Dynamic IP and Port (DIPP) translation, an oversubscription rate can be configured to multiply the number of times that the same translated IP address and port pair can be used concurrently. The rate is 1, 2, 4, or 8. The default setting is based on the firewall model.
    • A rate of 1 means no oversubscription; each translated IP address and port pair can be used only once at a time.
    • If the setting is Platform Default, user configuration of the rate is disabled and the default oversubscription rate for the model applies.
    Reducing the oversubscription rate decreases the number of source device translations, but provides higher NAT rule capacities.
  6. Tune accelerated aging settings.
    Select Accelerated Aging to enable faster aging-out of idle sessions. You can also change the threshold (%) and scaling factor:
    • Accelerated Aging Threshold—Percentage of the session table that is full when accelerated aging begins. The default is 80%. When the session table reaches this threshold (% full), PAN-OS applies the Accelerated Aging Scaling Factor to the aging calculations for all sessions.
    • Accelerated Aging Scaling Factor—Scaling factor used in the accelerated aging calculations. The default scaling factor is 2, meaning that the accelerated aging occurs at a rate twice as fast as the configured idle time. The configured idle time divided by 2 results in a faster timeout of one-half the time. To calculate the session’s accelerated aging, PAN-OS divides the configured idle time (for that type of session) by the scaling factor to determine a shorter timeout.
    For example, if the scaling factor is 10, a session that would normally time out after 3600 seconds would time out 10 times faster (in 1/10 of the time), which is 360 seconds.
  7. Enable packet buffer protection.
    1. Select Packet Buffer Protection to enable the firewall to take action against sessions that can overwhelm the its packet buffer and causes legitimate traffic to be dropped; enabled by default.
    2. If you enable packet buffer protection, you can tune the thresholds and timers that dictate how the firewall responds to packet buffer abuse.
      • Alert (%): When packet buffer utilization exceeds this threshold, the firewall creates a log event. The threshold is set to 50% by default and the range is 0% to 99%. If the value is set to 0%, the firewall does not create a log event.
      • Activate (%): When a packet buffer utilization exceeds this threshold, the firewall applies random early drop (RED) to abusive sessions. The threshold is set to 80% by default and the range is 0% to 99%. If the value is set to 0%, the firewall does not apply RED.
      Alert events are recorded in the system log. Events for dropped traffic, discarded sessions, and blocked IP address are recorded in the threat log.
      • Block Hold Time (sec): The amount of time a RED-mitigated session is allowed to continue before it is discarded. By default, the block hold time is 60 seconds. The range is 0 to 65,535 seconds. If the value is set to 0, the firewall does not discard sessions based on packet buffer protection.
      • Block Duration (sec): This setting defines how long a session is discarded or an IP address is blocked. The default is 3,600 seconds with a range of 0 seconds to 15,999,999 seconds. If this value is set to 0, the firewall does not discard sessions or block IP addresses based on packet buffer protection.
  8. Enable buffering of multicast route setup packets.
    1. Select Multicast Route Setup Buffering to enable the firewall to preserve the first packet in a multicast session when the multicast route or forwarding information base (FIB) entry does not yet exist for the corresponding multicast group. By default, the firewall does not buffer the first multicast packet in a new session; instead, it uses the first packet to set up the multicast route. This is expected behavior for multicast traffic. You only need to enable multicast route setup buffering if your content servers are directly connected to the firewall and your custom application cannot withstand the first packet in the session being dropped. This option is disabled by default.
    2. If you enable buffering, you can also tune the Buffer Size, which specifies the buffer size per flow. The firewall can buffer a maximum of 5,000 packets.
      You can also tune the duration, in seconds, for which a multicast route remains in the routing table on the firewall after the session ends by configuring the multicast settings on the virtual router that handles your virtual router (set the Multicast Route Age Out Time (sec) on the MulticastAdvanced tab in the virtual router configuration.
  9. Save the session settings.
    Click OK.
  10. Tune the Maximum Segment Size (MSS) adjustment size settings for a Layer 3 interface.
    1. Select NetworkInterfaces, select Ethernet, VLAN, or Loopback, and select a Layer 3 interface.
    2. Select AdvancedOther Info.
    3. Select Adjust TCP MSS and enter a value for one or both of the following:
      • IPv4 MSS Adjustment Size (range is 40 to 300 bytes; default is 40 bytes).
      • IPv6 MSS Adjustment Size (range is 60 to 300 bytes; default is 60 bytes).
    4. Click OK.
  11. (PAN-OS 12.2.2 and later) Prevent discarded UDP sessions from being kept alive by continuous traffic.
    By default, when the firewall places a UDP session in the DISCARD state, every subsequent packet that matches the same session (6-tuple) resets the session's idle timeout. Because UDP is connectionless and reuses the same source and destination ports, a continuously talking source can keep a discarded session alive indefinitely, so the session never ages out. This can block legitimate traffic that later reuses the same 6-tuple, causing it to be silently dropped until the discard session is cleared manually.
    To stop discarded UDP sessions from being refreshed—so they expire naturally on their discard timeout regardless of continued traffic—run:
    set session no-refresh-on-discard yes
    This is an operational setting (it is not part of the saved configuration) and persists across reboots. You must set it on each firewall independently, including both peers in an HA pair. This command is available in PAN-OS 12.2.2 and later.
    The setting applies to UDP sessions that are discarded through the following validated deny paths, which are the scenarios known to cause traffic disruption:
    • Session rematch—A UDP session that an App-ID or security-policy rematch now denies. Covers sessions that get stuck in DISCARD after a content update or a security-policy change, including GRE tunnels and SIP.
    • App-ID policy deny—A UDP session denied by an App-ID policy lookup. Covers DHCP, SIP, and other UDP applications denied by policy—for example after a tunnel or route goes down. (Other App-ID deny reasons, such as a policy-lookup error, are not affected.)
    • Host-service deny—A UDP session to a firewall host service that the management plane does not support or allow. Covers cases such as a delayed RADIUS reject where subsequent authentication requests reuse the same source port.
    • DNS Security deny—A UDP DNS session denied by a DNS Security action of drop-packet. Covers DNS sinkholing and blocked-domain responses where an internal DNS server keeps re-querying with the same 6-tuple. (Sessions explicitly marked no-discard are exempt.)
    • Threat mitigation drop-all—A UDP session denied by a threat-mitigation drop-all action when no block or response page is sent. If a block page is sent instead, the session continues to refresh so the client can retry.
    The setting does not affect:
    • TCP and other non-UDP protocols—TCP is connection-oriented; a new connection uses a new source port and therefore a new session, so a stale discard session simply times out on its own.
    • Sessions that display a block page or are otherwise retry-sensitive—These continue to refresh so the client can retry and receive the response.
    IPsec-tunneled UDP and other UDP flows are covered only when they are discarded through one of the deny paths listed above. TCP-based protocols such as BGP are not affected by this setting.
    To verify the setting is active, run show session info and confirm the output displays:
    Do not refresh discard sessions: True
  12. Commit your changes.
    Click Commit.
  13. Reboot the firewall after changing the jumbo frame configuration.
    1. Select DeviceSetupOperations.
    2. Click Reboot Device.