Advanced Settings
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.40 Locally Managed Administration Guide | 126
Aggressive
Aging
Attribute
Description
Multiple
parameters
Aggressive Aging helps manage the connections table capacity and
memory consumption of the firewall to increase durability and stability.
Aggressive Aging introduces a new set of short timeouts called aggressive
timeouts. When a connection is idle for more than its aggressive timeout it is
marked as "eligible for deletion". When the connections table or memory
consumption reaches the user defined threshold, Aggressive Aging begins
to delete "eligible for deletion" connections, until memory consumption or
connections capacity decreases back to the desired level.
Aggressive Aging allows the gateway machine to handle large amounts of
unexpected traffic, especially during a Denial of Service attack.
If the defined threshold is exceeded, each incoming connection triggers the
deletion of ten connections from the "eligible for deletion" list. An additional
ten connections are deleted with every new connection until the memory
consumption or the connections capacity falls below the enforcement limit. If
there are no "eligible for deletion" connections, no connections are deleted
at that time, but the list is checked after each subsequent connection that
exceeds the threshold.
Timeout settings are a key factor in memory consumption configuration.
When timeout values are low, connections are deleted faster from the table,
enabling the firewall to handle more connections concurrently. When
memory consumption exceeds its threshold, it is best to work with shorter
timeouts that can maintain the connectivity of the vast majority of the traffic.
The major benefit of Aggressive Aging is that it starts to operate when the
machine still has available memory and the connections table is not entirely
full. This way, it reduces the chances of connectivity problems that might
have occurred under low-resource conditions.
Table: Aggressive Aging Attributes