What is the default session distribution policy in the PA-7000 Series?
(
PA-7000 Series firewalls only
) New sessions are assigned to a DP on the same NPC on which the first packet of the session arrived. The selection of the DP is based on the session-load algorithm but, in this case, sessions are limited to the DPs on the ingress NPC.
Depending on the traffic and network topology, this policy generally decreases the odds that traffic will need to traverse the switch fabric.
Use this policy to reduce latency if both ingress and egress are on the same NPC. If the firewall has a mix of NPCs (PA-7000 20G and PA-7000 20GXM for example), this policy can isolate the increased capacity to the corresponding NPCs and help to isolate the impact of NPC failures.
Janey
1 day agoRory
7 days agoSage
12 days agoPhil
17 days agoAlida
22 days agoDenise
27 days agoCarmela
1 month agoKirby
1 month agoDenny
1 month agoAlethea
2 months agoLindsay
2 months agoDana
2 months agoMozelle
2 months agoDarci
2 months agoErick
2 months agoTamekia
3 months agoAllene
3 months agoJarvis
3 months agoCandida
3 months ago