Report post

What does aged-out mean in Palo Alto firewall?

@PPradhan, An aged-out response really just means the firewall never saw a tcp-fin and the session aged-out without a graceful termination. As long as you have a rulebase entry allowing the traffic, the traffic will be allowed through the firewall. Solved: Hi All, I have a doubt regarding aged-out feature in palo alto firewall.

What does aged-out mean in a TCP session?

If it is a TCP session and aged-out is the session end reason, the client did not receive a response back from the destination host and the session never established. Aged-Out may be referring to that the session had no responses so look at the session detail to see if the packets were sent but not received.

Why is a session end 'aged-out'?

For services using TCP however, having a session end "aged-out" might not be considered normal and further investigation is required. The reasons can be many. Here are just a few examples: This often goes hand-in-hand with application showing as ' Incomplete ' in the traffic logs.

The World's Leading Crypto Trading Platform

Get my welcome gifts