CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Services
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-12
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 534
Rep Power: 10
BarryStiefel has disabled reputation
Default Disable TCP timeout for one service

Disable TCP timeout for one service



In 3.0 versions of FireWall-1, you could eliminate them by setting the timeout to zero for either a specific service or by setting the TCP_TIMEOUT value to zero. In 4.0 and 4.1, a zero timeout results in a 60 second timeout. There is no way to disable TCP Timeouts in FireWall-1 4.x, though you can always set the TCP Timeout to the maximum, which is 24 hours.

In NG FP3 HF2 (and possibly AI), a zero timeout corresponds to the default timeout of 3600 seconds. If you absolutely need to disable timeouts for a service because the vendor of your application refuses to implement a "heart beat", this is how you would do it:

From dbedit, type:modify services timeout 2147483647update services Alternatively, make the same change through GUIDbEdit.



Remarks:
  1. Currently, there is no way to configure it from the GUI, since GUI blocks values larger then 9999.
  2. The value above is used internally by the kernel to specify infinite-time connections. However, if you set any smaller number in that range, you still get connections that should last many years.

I don't even want to think about the security implications of leaving idle TCP connections open forever, but my gut tells me that this is not a good idea. I do know that SecuRemote will misbehave if the timeout is set to zero. Other things will probably misbehave as well. PhoneBoy does not recommend doing this.

-- GuyR - 12 Jan 2004

FAQForm FAQs.Class: ServicesFAQs FAQs.OS: FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 15:48.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0