JUNOS software terminates sessions normally in certain situations—for example, after receiving a TCP FINish Close or receiving a RST (reset) message, when encountering Internet Control Message Protocol (ICMP) errors for UDP, and when no matching traffic is received before the service timeout. When sessions are terminated, their resources are freed up for use for other sessions.
To control when sessions are terminated, you configure the services gateway to age out sessions after a certain period of time, when the number of sessions in the session table reaches a specified percentage, or both.
- set security flow tcp-session tcp-initial-timeout 280
- set security flow tcp-session rst-invalidate-session