<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[NAT reflection disconnects after 20s idle]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I enabled NAT reflection in order to be able to access services from inside the LAN the same way as I would do it from outside. It works, only that the connection is dropped after exactly 20s if idle.</p>
<p dir="auto">For a test (replicating the problem) you can do the following: Create a port redirection for SSH (or any other interactive TCP connection) to an internal SSH capable pc and enable reflection. From outside my LAN I can now ssh in without any problems no matter how long I stay idle. From inside the LAN the connection will be dropped after 20s idletime. Hence ONLY the reflected connection is affected.</p>
<p dir="auto">Everything works if I generate traffic. However generating enough traffci is not a solution, since I need a jabber server (uses TCP 5222) inside the LAN (access via the WAN adress in order to not need to change if ouside the LAN) with the result that it keeps me logging in and out periodically.</p>
<p dir="auto">This question was already asked, however there was no solution yet. I tried different settings for keeping the state for the original port redirection rule with no influence. Also changing the general optimisation policy does not change the above described behaviour.</p>
<p dir="auto">Since I'm not (yet) so familiar with pf could someone point me towards where e.g. the timeouts for states are set? I see the /etc/pf.conf does not contain anything usefull (doesn't seem to be used at all).</p>
<p dir="auto">Can sombody help? It's easy to replicate - just use putty and ssh and wait for 20s - the connection will drop..</p>
<p dir="auto">Regards<br />
Arno</p>
]]></description><link>https://forum.netgate.com/topic/4422/nat-reflection-disconnects-after-20s-idle</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 07:01:34 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/4422.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 05 May 2007 18:00:54 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to NAT reflection disconnects after 20s idle on Sun, 06 May 2007 20:29:50 GMT]]></title><description><![CDATA[<p dir="auto">Now I found the right thread: http://forum.pfsense.org/index.php/topic,1528.0.html - don't know why I didnt find it earliear when i was trying to solve the problem myself :( sorry for the trouble.</p>
<p dir="auto">Thanks<br />
Arno</p>
]]></description><link>https://forum.netgate.com/post/154234</link><guid isPermaLink="true">https://forum.netgate.com/post/154234</guid><dc:creator><![CDATA[wacko]]></dc:creator><pubDate>Sun, 06 May 2007 20:29:50 GMT</pubDate></item><item><title><![CDATA[Reply to NAT reflection disconnects after 20s idle on Sun, 06 May 2007 19:23:30 GMT]]></title><description><![CDATA[<p dir="auto">The change is already made in that version and it should be a lot longer than 20 seconds.  The folks that requested it even verified that the change worked.  All discussed in this forum.</p>
]]></description><link>https://forum.netgate.com/post/154227</link><guid isPermaLink="true">https://forum.netgate.com/post/154227</guid><dc:creator><![CDATA[sullrich]]></dc:creator><pubDate>Sun, 06 May 2007 19:23:30 GMT</pubDate></item><item><title><![CDATA[Reply to NAT reflection disconnects after 20s idle on Sun, 06 May 2007 19:07:07 GMT]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">thanks for the response. I was already using 1.2-BETA (pfSense-Full-Update-1.2-BETA-1-TESTING-SNAPSHOT-05-04-07.tgz downloaded on 0505). Did you make the change later? I will look now for the hidden option (i suppose in the config.xml?)</p>
<p dir="auto">Thanks<br />
Arno</p>
]]></description><link>https://forum.netgate.com/post/154226</link><guid isPermaLink="true">https://forum.netgate.com/post/154226</guid><dc:creator><![CDATA[wacko]]></dc:creator><pubDate>Sun, 06 May 2007 19:07:07 GMT</pubDate></item><item><title><![CDATA[Reply to NAT reflection disconnects after 20s idle on Sat, 05 May 2007 18:26:09 GMT]]></title><description><![CDATA[<p dir="auto">Upgrade to 1.2-BETA-1.  The timeout has been set to 1 hour and there is a hidden configurable option in there forum if this is not enough.</p>
]]></description><link>https://forum.netgate.com/post/154165</link><guid isPermaLink="true">https://forum.netgate.com/post/154165</guid><dc:creator><![CDATA[sullrich]]></dc:creator><pubDate>Sat, 05 May 2007 18:26:09 GMT</pubDate></item></channel></rss>