- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello community,
there are various timeouts set for the firewall state machine in global properties of the management domain.
TCP start
TCP session
TCP end
UDP virtual session
ICMP virtual session
Other IP virtual session
SCTP start
SCTP session
SCTP end
I know that we can override the session timeouts for TCP, UDP, ICMP, other IP and SCTP by modifying the advanced properties of the service object used in the relevant firewall rule.
I have a specific usecase, where I want to override the TCP start timeout, without changing it for all gateways in this management domain. Override per gateway would be nice, override per service object even better.
As far as I know, this is not possible. Am I right with that? Does anyone know a way to do so?
R80.30 T200 Jumbo HFA T50
Thank you for your thoughts!
Actually it is possible to locally override the TCP start and end timeouts out on the gateway with the following kernel variables:
tcp_local_start_timeout
tcp_local_end_timeout
These are mentioned here:
There is very little documentation for these variables outside of the fact that they exist. The default value of both variables is 0, which I assume means that these values are inherited from the corresponding Stateful Inspection settings that are part of the SMS/Domain/CMA. I would also assume that setting these to a nonzero value overrides that, and that the units to use with these variables is seconds. I suppose it could be milliseconds though, so I would strongly advise getting this clarified with TAC or trying it in a lab first before tampering with these variables on a production firewall. If the units do happen to be milliseconds, setting these variables to 1 would probably cause a major outage.
There does not seem to be a way to locally override the start and end timeout variables for individual service objects that I can see.
Thank you, Tim!
I will ask TAC referring to this sk and share the answer here later.
I got the confirmation from TAC.
Quote:
These values are in seconds and you need to change it for all the gateway individually.
Note : Please change the values in lean hours.
Maybe you guys know it, but TAC missed to tell us and sk33285 (and sk26202) also don't drop a hint, so I want to share this:
Changing this kernel parameter requires an access policy install on this gateway to take effect.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY