Specifying persistent sessions
This task is for only TCP sessions in ESTABLISHED state. You can specify TCP sessions that match the
permit statements in the specified ACL as persistent sessions, and set longer lifetime or never-age-out
persistent sessions. A never-age-out session is not removed until the device receives a connection close
request from the initiator or responder, or you manually clear the session entries.
For a TCP session in ESTABLISHED state, the priority order of the associated aging time is as follows:
Aging time for persistent sessions.
•
Aging time for sessions of application layer protocols.
•
Aging time for sessions in different protocol states.
•
To specify persistent sessions:
Step
1.
Enter system view.
2.
Specify persistent
sessions.
Setting the maximum number of sessions
Perform this task to prevent too many session entries from affecting other services.
When the upper limit is reached, the device does not establish more sessions or create more session
entries until the number of sessions on the device drops below the upper limit.
To set the maximum number of sessions:
Task
1.
Enter system view.
2.
Set the maximum number of
sessions.
Configuring session logging
Session logs provide information about user access, IP address translation, and network traffic for
security auditing. These logs are sent to the log server or the information center.
The device supports time-based or traffic-based logging:
Time-based logging—The device outputs session logs at an interval.
•
•
Traffic-based logging—The device outputs a session log when the traffic amount of a session
reaches a threshold. After outputting a session log, the device resets the traffic counter for the
session. The traffic-based thresholds can be byte-based and packet-based. If you set both thresholds,
the last configuration takes effect.
Command
system-view
session persistent acl [ ipv6 ] acl-number
[ aging-time time-value ]
Command
system-view
session max-entries max-value
263
Remarks
N/A
By default, no persistent sessions are
specified.
Remarks
N/A
The default setting depends on
your device model.