• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

TCP connection timeout problems

Scheduled Pinned Locked Moved 2.1 Snapshot Feedback and Problems - RETIRED
6 Posts 3 Posters 8.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • B
    bfranske
    last edited by Dec 18, 2012, 6:38 PM

    Hi,
    We've been working with the 2.1 beta and have been experiencing some problems with long lived TCP sessions timing out. It seems to be the case that both inbound and outbound TCP sessions seem to go away after 15 minutes has passed on the next :00 :15 :30 and :45 and then on every :00 :15 :30 :45.

    A major problem with that for us is that inbound OpenVPN sessions (running in TCP mode) are killed every 15 minutes as well as large file downloads that get killed after 15 minutes. Obviously these sessions should not be timing out as they are carrying active traffic.

    One, perhaps strange, consideration in our setup is that we have both IPv4 and IPv6 (native, not tunneled) but the IPv4 traffic has to leave on a different interface than the IPv6 traffic. More specifically IPv4 traffic is exiting on em1 and IPv6 traffic is exiting on em0_vlan301.

    Any suggestions? Thanks!

    1 Reply Last reply Reply Quote 0
    • J
      jimp Rebel Alliance Developer Netgate
      last edited by Dec 18, 2012, 7:13 PM

      Check your system logs, on the main system tab as well as the Gateways tab.

      It sounds like the states are getting cleared because a gateway is shown as down, or something similar to that.

      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • B
        bfranske
        last edited by Dec 18, 2012, 7:30 PM

        Good hunch, our IPv4 gateway is shown as down even though it is not. I'm assuming the gateway checks are done via ping? That is blocked on this upstream gateway and unfortunately I am not the admin for that system and am unable to get ICMP echos enabled on it.

        Thanks!

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Dec 18, 2012, 9:23 PM

          Yep, you can either disable gateway monitoring, or disable the state killing option under System > Advanced on the Misc tab

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • G
            gerdesj
            last edited by Dec 18, 2012, 11:06 PM

            @bfranske:

            Good hunch, our IPv4 gateway is shown as down even though it is not. I'm assuming the gateway checks are done via ping? That is blocked on this upstream gateway and unfortunately I am not the admin for that system and am unable to get ICMP echos enabled on it.

            Thanks!

            You might like to try one of these for monitoring: 8.8.8.8 or 8.8.4.4 or 4.2.2.1,2,3 (look them up!)  They are all very reliable and reasonably local to "anywhere".

            Cheers
            Jon

            1 Reply Last reply Reply Quote 0
            • B
              bfranske
              last edited by Dec 19, 2012, 6:47 PM

              I found the setting for disabling state killing and that took care of it.

              Thanks!
              -Ben

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received