VMware Cloud Community
schistad
Enthusiast
Enthusiast

vShield Edge firewall: Connection state tracking table timeout adjustable?

I am surprised that this is not mentioned anywhere but network security folks here may know that stateful firewalls such as vShield Edge need to maintain a table of all known established (accepted) sessions so that related packets can be accepted. To avoid this table growing into infinity, a timer is associated with each entry in this table which gets refreshed every time a related packet passes through. If a connection stays silent past a defined 'timeout' value, its entry is removed from the state table.

This works fairly well for protocols which establish sessions on the fly as they are needed, and tear them down immediately afterwards. It works less well with protocols that are long-lived but low frequency, such as an SSH connection. Hence, commercial firewalls have a tunable setting for this timeout value which can (and often is) be set to many hours.

However, in vShield Edges case there is no documented way to tweak this setting, and it is indeed quite low - it seems to be around 5 minutes which is an old default from many other implementations. 5 minutes is extremely aggressive however, and causes all sorts of annoyances including the need to constantly restart SSH connections (5 minutes timeout means that a coffee break is enough to drop your SSH session).

Does anyone know where this value is stored and if perhaps there is a way of adjusting it?

0 Kudos
2 Replies
m5pbh
Contributor
Contributor

I too believe I am seeing the same issue with vShield App and SSH sessions dropping but like you can find nothing in any guide or web search about how to change this. The lack of good quality, in depth documentation around vShield surprises me some what. We are just about to move to vCloud 5.1.2 and VCNS - I hope the documentation and implementations of network security are better in this newly branded product.

0 Kudos
schistad
Enthusiast
Enthusiast

Hei,

Jeg er på ferie i perioden 26/8 til 9/9. Mail vil ikke bli lest i denne perioden, så det er smart å ta kontakt på nytt etter min retur for viktige henvendelser Smiley Happy

--

Ole

0 Kudos