<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Session will not go away in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Session-will-not-go-away/m-p/136937#M20719</link>
    <description>&lt;P&gt;A "session" exists only as a logging construct.&amp;nbsp; Individual connections (when bundled together by the gateway) comprise a session.&amp;nbsp; The techniques you mentioned are to kill a connection (or connections) and do work.&amp;nbsp; However when a new connection starts back up after the kill that is substantially similar to the previous ones being tracked by a current session, that connection is added back in to the existing session for logging purposes and that is what you are seeing.&lt;/P&gt;
&lt;P&gt;If you'd rather not see these session logs, just uncheck "per Session" in the properties of the Track column for the matched rule, and make sure "per Connection" is checked there instead which will give you the more traditional per connection logs which will show that your connection-killing efforts are working as expected.&lt;/P&gt;
&lt;P&gt;All I can say for the moment is that some clarity on this somewhat confusing issue is hopefully on the way, and may be delivered in a very public forum in the near future by someone well known here at CheckMates.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Dec 2021 03:38:34 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2021-12-22T03:38:34Z</dc:date>
    <item>
      <title>Session will not go away</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Session-will-not-go-away/m-p/136934#M20718</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;hope someone knows how to get rid of this:&lt;/P&gt;&lt;P&gt;we have some load balancers in the DMZ pointing to an internal web server.&lt;/P&gt;&lt;P&gt;Now we want to implement SSL inbound inspection into this connection (log4j &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; )&lt;/P&gt;&lt;P&gt;Rules for this are set -&amp;gt; ok but the connection will not get inspected because the session will not stop. We tried everything we know: Stop/reboot of the load balancers, stop/reboot of the web server. kicked connection via this skript &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/How-to-delete-an-specific-entry-from-the-Connections-Table-with/m-p/99220/highlight/true" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/How-to-delete-an-specific-entry-from-the-Connections-Table-with/m-p/99220/highlight/true&lt;/A&gt; also created a rule to drop the connection then removed the rule. But still it uses some "old" session as you can see the screen shot.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2021-12-21_21-35.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14660iBCD565FD304F674E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2021-12-21_21-35.png" alt="2021-12-21_21-35.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;plz hlp!&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;David&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 20:39:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Session-will-not-go-away/m-p/136934#M20718</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2021-12-21T20:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Session will not go away</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Session-will-not-go-away/m-p/136937#M20719</link>
      <description>&lt;P&gt;A "session" exists only as a logging construct.&amp;nbsp; Individual connections (when bundled together by the gateway) comprise a session.&amp;nbsp; The techniques you mentioned are to kill a connection (or connections) and do work.&amp;nbsp; However when a new connection starts back up after the kill that is substantially similar to the previous ones being tracked by a current session, that connection is added back in to the existing session for logging purposes and that is what you are seeing.&lt;/P&gt;
&lt;P&gt;If you'd rather not see these session logs, just uncheck "per Session" in the properties of the Track column for the matched rule, and make sure "per Connection" is checked there instead which will give you the more traditional per connection logs which will show that your connection-killing efforts are working as expected.&lt;/P&gt;
&lt;P&gt;All I can say for the moment is that some clarity on this somewhat confusing issue is hopefully on the way, and may be delivered in a very public forum in the near future by someone well known here at CheckMates.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 03:38:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Session-will-not-go-away/m-p/136937#M20719</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-12-22T03:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: Session will not go away</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Session-will-not-go-away/m-p/136939#M20720</link>
      <description>&lt;P&gt;Very good to know thank you!!&lt;/P&gt;&lt;P&gt;Now I need to find out why the https inspection rule is not matching &lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt; but this will not be handled in this forum thread.&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;David&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 21:53:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Session-will-not-go-away/m-p/136939#M20720</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2021-12-21T21:53:56Z</dc:date>
    </item>
  </channel>
</rss>

