Skip to main content
aseques
Visitor III
July 21, 2016
Question

Configure session ttl limit between two interfaces?

  • July 21, 2016
  • 4 replies
  • 6459 views

I had to lower the value for the session-ttl because the fw was having issues with memory. But now, I'm suffering issues when the traffic is going from DMZ to internal (due to interrupted connections).

Is there any way to configure the session-ttl per interface? I see there are four modes here

[ul]
  • Application Control Sensor entry (if applicable)
  • Custom Service (if applicable)
  • Policy (if applicable)
  • System #   <--- Lowest level[/ul]

    Any ideas?

     

    • 4 replies

      jintrah_FTNT
      Staff
      Staff
      July 21, 2016

      No, session-ttl settings are not available at interface level. You can apply the ttl on those policies using the dmz and internal interfaces

      aseques
      asequesAuthor
      Visitor III
      July 21, 2016

      Ok, I feared that, but can I add the "set timeout-send-rst enable" globally? Does it have any side issues, because so far all the issues I had are because of the endpoint not being notified of the closed connection.

      Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
      Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!