
Palo Alto Networks PAN-OS 6.1 Release Notes • 13
PAN-OS 6.1 Release Information Features Introduced in PAN-OS 6.1
Remove TCP Timestamp
A new Remove TCP Timestamp option has been added to the Zone Protection profile to
enable you to strip the TCP timestamp from the TCP header. This option is available in the
web interface and in the CLI.
TCP Session Closing
Timers
Two new timers have been added (TCP Time Wait and TCP Unverified RST) and the
tcp-wait timer has been renamed the TCP Half Closed timer, as detailed below:
• The TCP session termination procedure now has a TCP Half Closed timer, which is
triggered by the first FIN the firewall sees for a session, and a second timer (TCP Time
Wait), which is triggered by the second FIN or a RST. You can set these timers globally
or per application. In prior releases, only one TCP wait timer existed, triggered by the first
FIN. If that setting was too short, the half-closed sessions could be closed prematurely.
Conversely, a setting that was too long could make the session table grow too much and
possibly use up all of the sessions. By having two timers, a relatively long TCP Half Closed
timer allows the opposite side time to respond, and a short TCP Time Wait timer quickly
ages fully closed sessions and controls the size of the session table.
• A TCP Unverified RST timer has been added at the global level. If the firewall receives a
RST that cannot be verified (because it has an unexpected sequence number within the
TCP window or it is from an asymmetric path), the TCP Unverified RST timer controls
the aging out of the session. This timer provides an additional security measure.
Session End Reason
Logging
When troubleshooting connectivity and application availability issues, knowing what caused
a session to terminate can be useful. PAN-OS now provides a new session end reason field
in traffic logs. Session end reasons can also be included in reports that are generated based
on traffic logs and SNMP traps and email alerts that are triggered by traffic logs contain
session end reasons, as well.
New Networking Feature Description
Kommentare zu diesen Handbüchern