Security Mode Configuration Commands
167
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
security-config[session-limit]>
conn_limit_type Percentage_Of_MaxSessions
security-config[session-limit]>
user_limit 80
security-config[session-limit]>
block_new_session Block_IP_to_add_new_session
security-config[session-limit]>
block_IP_to_add_new_session_for_time 60
security-config[session-limit]>
save
Related show command: show security firewall session_limit
security firewall session_settings configure
This command configures global session time-outs. After you have issued the security
firewall session_settings configure command, you enter the
security-config [session-settings] mode, and then you can configure one keyword and
associated parameter or associated keyword at a time in the order that you prefer.
Command example:
SRX5308>
security firewall session_settings configure
security-config[session-settings]>
tcp_session_timeout 3600
security-config[session-settings]>
udp_session_timeout 180
security-config[session-settings]>
icmp_session_timeout 120
security-config[session-settings]>
save
Related show command: show security firewall session_settings
Step 1 Format security firewall session_settings configure
Mode security
Step 2 Format tcp_session_timeout <seconds>
udp_session_timeout <seconds>
icmp_session_timeout <seconds>
Mode security-config [session-settings]
Keyword Associated Parameter
to Type
Description
tcp_session_timeout seconds Specifies the TCP session timeout period (integer) in
seconds.
udp_session_timeout seconds Specifies the UDP session timeout period (integer) in
seconds.
icmp_session_timeout seconds Specifies the ICMP session timeout period (integer) in
seconds.