CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Services
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-10-31
munit_si@yahoo.com munit_si@yahoo.com is offline
Junior Member
 
Join Date: 2006-02-21
Posts: 28
Rep Power: 0
munit_si@yahoo.com has an average reputation (10+)
Default Strange Timeout issue in Checkpoint

We have default tcp timeout set on Checkpoint firewall to 1 hr. Now problem which we are facing is that our connection after 1 hr of inactivity still persist (hanging login sessions still there) between the client and pc(example our ssh sessions)

we are using NG55 AI W

my question is


1) When idle timeout is reached for tcp , is the connection removed from the connection table only or is reset also issued to the client and server

2) any idea how to avoid this issue


any help is highly appreciated
Reply With Quote
  #2 (permalink)  
Old 2006-10-31
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 726
Rep Power: 2
northlandboy has an average reputation (10+)
Default Re: Strange Timeout issue in Checkpoint

No reset is sent. The connection is removed from the connection table, and the next packet that comes along will be marked as out of state, and dropped. Generally you don't want to send rejects for out of state traffic.

Try changing the tcp_keepalive_interval on your server to less than an hour, if you want those connections to stay alive.
Reply With Quote
  #3 (permalink)  
Old 2006-10-31
munit_si@yahoo.com munit_si@yahoo.com is offline
Junior Member
 
Join Date: 2006-02-21
Posts: 28
Rep Power: 0
munit_si@yahoo.com has an average reputation (10+)
Default Re: Strange Timeout issue in Checkpoint

Thanks a lot. But what does the below article means from checkpoint. It says that reset is being issued now as per the fix.


snippets below from the checkpoint site


Symptoms

* Application needs to receive a reset (RST) or FIN from the Security gateway after 3 minutes of inactivity indicating connection timeout.

Solution
VPN-1/FireWall-1 records all TCP connections with a certain timeout. Default timeout is one hour. When timeout is reached, connection is deleted from connections table. Certain applications, where connections stay idle for a time, then communication is resumed, need reset (RST) packets sent to client and server upon connection timeout. These packets prompt client and server to return ACK packets with correct sequences. VPN-1/FireWall-1 then generates RST packets based on returned sequences.

This problem was fixed. The fix is included in the following release(s): VPN-1/FireWall-1 NG with AI R55 HFA R55_02.

Check Point recommends to always upgrade to a recent version, and to the most recent HFA (HotFix Accumulator) of this version
Reply With Quote
  #4 (permalink)  
Old 2006-10-31
munit_si@yahoo.com munit_si@yahoo.com is offline
Junior Member
 
Join Date: 2006-02-21
Posts: 28
Rep Power: 0
munit_si@yahoo.com has an average reputation (10+)
Default Re: Strange Timeout issue in Checkpoint

Also, is thier a way we can make it to send reset if required by the application on the server side to avoid this issue ?


I am using the NG55 AI w in my enviornment.




Thanks
Munit
Reply With Quote
  #5 (permalink)  
Old 2006-11-01
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 726
Rep Power: 2
northlandboy has an average reputation (10+)
Default Re: Strange Timeout issue in Checkpoint

Set tcp_keepalive_interval to less than an hour on your server.

And look into the fw_rst_expired_conn parameter. It may do what you want, but have a think about what you're doing.

You will note from the SK you looked up that articles in Check Point's KB are not always complete, or necessarily even accurate. Sometimes they're only really suited to internal use - you particularly notice this with the higher levels of access.
Reply With Quote
  #6 (permalink)  
Old 2006-11-01
munit_si@yahoo.com munit_si@yahoo.com is offline
Junior Member
 
Join Date: 2006-02-21
Posts: 28
Rep Power: 0
munit_si@yahoo.com has an average reputation (10+)
Default Re: Strange Timeout issue in Checkpoint

Thanks a lot.

Regards
Munit
Reply With Quote
  #7 (permalink)  
Old 2006-11-02
munit_si@yahoo.com munit_si@yahoo.com is offline
Junior Member
 
Join Date: 2006-02-21
Posts: 28
Rep Power: 0
munit_si@yahoo.com has an average reputation (10+)
Default Re: Strange Timeout issue in Checkpoint

Quote:
Originally Posted by northlandboy View Post
Set tcp_keepalive_interval to less than an hour on your server.

And look into the fw_rst_expired_conn parameter. It may do what you want, but have a think about what you're doing.

You will note from the SK you looked up that articles in Check Point's KB are not always complete, or necessarily even accurate. Sometimes they're only really suited to internal use - you particularly notice this with the higher levels of access.

Hi,

Thanks a lot for all ur help.

What is the more preffered way(recommended) setting up the fw_rst_expired_conn parameter or settings up the tcp_keepalive_interval on the server ? Reason why I am asking is as I have to decide atleast one of these solutions.

Regards
Munit
Reply With Quote
  #8 (permalink)  
Old 2006-11-02
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 726
Rep Power: 2
northlandboy has an average reputation (10+)
Default Re: Strange Timeout issue in Checkpoint

Depends what you want to do. I would change the server, or possibly increase the service timeout in CP. I've seen very little documentation for that other parameter, so I personally would be wary of it.

But I know nothing about your network, or your site policies. I have no idea if you can even change that parameter on your server, as I don't know what OS you are using. I don't know how the politics work at your site, or what is possible.

You will need to look at each of the three potential solutions, and make a decision based on what is best for your site. Try and understand the implications of each of the potential fixes first.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:35.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0