< Home

firewall session fast-aging enable

Function

The firewall session fast-aging enable command enables the fast session aging function.

The undo firewall session fast-aging enable command disables the function.

Format

firewall session fast-aging enable

undo firewall session fast-aging enable

Parameters

None

Views

System view

Default Level

2: Configuration level

Usage Guidelines

By default, the function is enabled.

In some scenarios, when the number of concurrent sessions on the FW increases quickly due to a network attack, sessions cannot be created for normal services.

In this case, you can enable fast session aging. When the usage of the session table reaches the threshold configured using the firewall session fast-aging upper-threshold threshold command, the FW accelerates the aging process based on the session timeout time and the percentage configured using the firewall session fast-aging early-ageout percent command, which reduces the session table usage.

The fast session aging function does not take effect for persistent-connection sessions, and sessions with TCP/SCTP connections being established or disconnected.

Example

# Enable the fast session aging function.

<sysname> system-view
[sysname] firewall session fast-aging enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >