Best practise

Hi

I have a few CCR that I use as BGP peering points. Which means I have asym routing. With that in mind tcp session time out. Currently set at 1d, I am thinking i should lower this as I might get packets from the stream showing up across multiple CCR’s. I have rules in place to handle tcp non Syn packets.

Whats the down side to rebuilding the session .. if I lower it to say 2 hours ?

A

With asymmetric routing you should never use connection tracking!