Configure Session Timeouts (SCM)
Focus
Focus
Next-Generation Firewall

Configure Session Timeouts (SCM)

Table of Contents


Configure Session Timeouts (SCM)

Procedure for configuring session timeouts in Strata Cloud Manager.
  1. Log in to Strata Cloud Manager.
  2. Select ManageConfigurationNGFW and Prisma AccessDevice SettingsDevice SetupSession ConfigurationNGFW and Prisma AccessDevice SettingsDevice SetupSessionand select the Configuration Scope where you want to configure the session timeout settings.
    You can select a folder or firewall from your Folders or select Snippets to configure the session timeout settings in a snippet.
  3. Configure the miscellaneous timeout settings.
    • Default (sec)—Maximum length of time that a TCP session remains open after it’s denied based on a Security policy configured on the firewall.
      Range is 1 to 15,999,999; default is 90.
    • Discard Default (sec)—Maximum length of time that a non-TCP/UDP session remains open after the firewall denies a session based on configured Security policies.
      Range is 1 to 15,999,999; default is 60.
    • Scan (sec)—Maximum length of time that any session remains open after it’s considered inactive; an application is regarded as inactive when it exceeds the application trickling threshold defined for the application
      Range is 5 to 30; default is 10.
    • Captive Portal (sec)—Authentication session timeout for the Authentication Portal web form. To access the requested content, the user must enter the authentication credentials in this form and be successfully authenticated
      Range is 1 to 15,999,999; default is 30.
  4. Configure the TCP timeout settings.
    • Discard TCP (sec)—Maximum length of time that a TCP session remains open after it’s denied based on a Security policy configured on the firewall.
      Range is 1 to 15,999,999; default is 90.
    • TCP (sec)—Maximum length of time that a TCP session remains open without a response, after a TCP session is in the Established state (after the handshake is complete, while data is being transmitted, or both).
      Range is 1 to 15,999,999; default is 3,600.
    • TCP Handshake (sec)—Maximum length of time permitted between receiving the SYN-ACK and the subsequent ACK to fully establish the session.
      Range is 1 to 60; default is 10.
    • TCP Init (sec)—Maximum length of time permitted between receiving the SYN and SYN-ACK before starting the TCP handshake timer.
      Range is 1 to 60; default is 5.
    • TCP Half Closed (sec)—Maximum length of time between receiving the first FIN and receiving the second FIN or an RST.
      Range is 1 to 604,800; default is 120.
    • TCP Time Wait (sec)—Maximum length of time after receiving the second FIN or an RST.
      Range is 1 to 600; default is 15.
    • Unverified RST—Maximum length of time after receiving an RST that can’t be verified (the RST is within the TCP window but has an unexpected sequence number, or the RST is from an asymmetric path).
      Range is 1 to 600; default is 30.
  5. Configure the UDP timeout settings.
    • Discard UDP (sec)—Maximum length of time that a UDP session remains open after it’s denied based on a Security policy configured on the firewall.
      Range is 1 to 15,999,999; default is 60.
    • UDP (sec)—Maximum length of time that a UDP session remains open without a UDP response.
      Range is 1 to 15,999,999; default is 30.
  6. Configure the ICMP timeout settings.
    • ICMP (sec)—Maximum length of time that an ICMP session can be open without an ICMP response.
      Range is 1 to 15,999,999; default is 6.
  7. Save.
  8. (Optional) Configure the remaining firewall session settings.
  9. Push Config to push your configuration changes.