Stateful Sessions
For TCP, the TOE tracks the full three-way handshake to establish stateful sessions:
SYN : Initial connection request from client.
SYN-ACK : Response from server.
ACK : Final acknowledgment from client.
A TCP session is established in the TOE only after this handshake is successfully observed. The TOE validates sequence numbers and ensures both endpoints have agreed to the connection.
TCP session maintenance includes:
-
Monitoring TCP flags (e.g., PSH, ACK, FIN, RST) to detect session teardown (a FIN or RST exchange) and initiate session removal.
-
Enforcing the correct sequence and state transitions (e.g., from SYN_SENT to ESTABLISHED).
-
Maintaining per-flow state in the session table.
-
Enforcing session removal based on idle timeouts (1800 seconds by default).
While UDP is stateless at the protocol level, the TOE treats UDP traffic in a session-like manner:
-
A session is created upon receipt of a valid UDP packet that matches a permitted policy.
-
The TOE creates a unidirectional or bidirectional flow entry in the session table based on source/destination IPs and ports.
-
There is no handshake; the session is considered active as long as matching UDP traffic continues.
UDP session maintenance includes:
-
Tracking each UDP flow’s parameters (source IP/port, destination IP/port).
-
Applying idle timeouts (60 seconds by default).
-
Removing the session after no matching traffic is observed for the configured timeout duration.
ICMP is not connection-oriented, but the TOE implements session tracking for ICMP messages such as Echo Request / Echo Reply.
ICMP session establishment:
-
When an ICMP request is observed and permitted by policy, the TOE creates a temporary session entry.
-
This session is considered ""established"" for the purpose of tracking the reply and enforcing policy symmetry.
ICMP Session maintenance:
-
The session exists briefly.
-
The session allows the associated ICMP reply message (e.g., Echo Reply).
-
Once the timeout (6 seconds by default) expires or the reply is seen, the session is removed.
The default timeout values can be modified as shown in the below configuration example:
user@host# set applications application test term test protocol tcp inactivity-timeout 2000
Use similar command to modify UDP and ICMP.