Managing System Services
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.40 Locally Managed Administration Guide | 268
General
n
Session timeout (in seconds)
- Time in seconds before the session times out.
n
Use source port
- Select this option and enter a port number for the client side service. If
specified, only those source port numbers are accepted, dropped, or rejected when inspecting
packets of this service. Otherwise, the source port is not inspected.
n
Accept replies
(relevant for non-TCP services) - When cleared, server to client packets are
treated as a different connection.
n
Match
(a highly advanced option to be used only by Check Point Support).
Connection handling
n
Keep connections open after policy has been installed
- Even if they are not allowed under
the new policy. If you change this setting, the change does not affect open connections, but
only future connections.
n
Synchronize connections on cluster
- Enables state-synchronized High Availability or Load
Sharing on a cluster. Of the services allowed by the Rule Base, only those with Synchronize
connections on cluster are synchronized as they pass through the cluster. By default, all new
and existing services are synchronized.
n
Start synchronizing X seconds after the connection was initiated
- For TCP services, enable
this option to delay telling the Quantum Spark Appliance about a connection so that the
connection is only synchronized if it still exists in X seconds after the connection is initiated.
Some TCP services (HTTP for example) are characterized by connections with a very short
duration. There is no point in synchronizing these connections because every synchronized
connection consumes gateway resources, and the connection is likely to have finished by the
time a failover occurs.
Aggressive aging
This feature can be configured from the
Device
>
Advanced
page. When the appliance is under load,
older connections are removed from memory faster to make room for new connections.
n
Enable aggressive aging
- Select this option to manage connections table capacity and
reduce gateway memory consumption to increase durability and stability.
n
Aggressive aging timeout (in seconds)
- Time in seconds before the session times out.
4. Click
Apply
.
To edit a service:
1. Select a service from the list.
2. Click
Edit
.
3. Make the necessary changes. Note that not all fields can be edited.
4. Click
Apply
.
To delete a service:
1. Select the service from the list. Note that you can only delete a user defined service.
2. Click
Delete
.
3. Click
Yes
in the confirmation message.