<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dropped &amp;quot;PSH-ACK&amp;quot; / Override Session Timeout questions in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dropped-quot-PSH-ACK-quot-Override-Session-Timeout-questions/m-p/118631#M16791</link>
    <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have recently moved our Client VPN Gateways from behind an OpnSense behind our Checkpoint Cluster.&lt;/P&gt;&lt;P&gt;Since then, one of our teams complain about connections resets of their applications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could see, that there are lots of "PSH-ACK" dropped out of state and after doing some investigation, I see that the default session timeout of OpnSense is set to 86400 Seconds vs. 3600 of Checkpoint.&lt;/P&gt;&lt;P&gt;I have then created a TCP Object, dealing with Ports 8440-8450 and set the Virtual Session Timeout to 86400 but the behaviour didn't change.&lt;/P&gt;&lt;P&gt;I have then checked via fw ctl conntab and could see, that the sessions were still created with 3600 sec.&lt;/P&gt;&lt;P&gt;&amp;lt;(inbound, src=[10.255.216.196,52396], dest=[10.49.2.138,8444], TCP); 1863/3015, rule=104, tcp state=TCP_ESTABLISHED, service=3600, conn modules: Authentication, FG-1&amp;gt;&lt;/P&gt;&lt;P&gt;So in the next step, I have created a dedicated object for port 8444 and now I can at least see, that the session timer is at 20879 sec.&lt;/P&gt;&lt;P&gt;&amp;lt;(inbound, src=[10.255.226.75,55032], dest=[10.49.2.138,8444], TCP); 20823/20879, rule=104, tcp state=TCP_ESTABLISHED, service=663, conn modules: Authentication, FG-1&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question one:&lt;/P&gt;&lt;P&gt;Does the virtual session timeout for port ranges not work?&lt;/P&gt;&lt;P&gt;Since this is matching an "any service" rule - could it be that our high port object (TCP-1024-64535) interferes here?&lt;/P&gt;&lt;P&gt;Both, the small port range and the high-ports have a "match any" flag. As per the logs, the correct object matched, though.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question two:&lt;/P&gt;&lt;P&gt;Why do I only see a session time of 20879 s in the conntab, while the time is set 86400 sec. in the port object.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Tue, 18 May 2021 12:02:38 GMT</pubDate>
    <dc:creator>T_Sonnberger</dc:creator>
    <dc:date>2021-05-18T12:02:38Z</dc:date>
    <item>
      <title>Dropped "PSH-ACK" / Override Session Timeout questions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dropped-quot-PSH-ACK-quot-Override-Session-Timeout-questions/m-p/118631#M16791</link>
      <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have recently moved our Client VPN Gateways from behind an OpnSense behind our Checkpoint Cluster.&lt;/P&gt;&lt;P&gt;Since then, one of our teams complain about connections resets of their applications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could see, that there are lots of "PSH-ACK" dropped out of state and after doing some investigation, I see that the default session timeout of OpnSense is set to 86400 Seconds vs. 3600 of Checkpoint.&lt;/P&gt;&lt;P&gt;I have then created a TCP Object, dealing with Ports 8440-8450 and set the Virtual Session Timeout to 86400 but the behaviour didn't change.&lt;/P&gt;&lt;P&gt;I have then checked via fw ctl conntab and could see, that the sessions were still created with 3600 sec.&lt;/P&gt;&lt;P&gt;&amp;lt;(inbound, src=[10.255.216.196,52396], dest=[10.49.2.138,8444], TCP); 1863/3015, rule=104, tcp state=TCP_ESTABLISHED, service=3600, conn modules: Authentication, FG-1&amp;gt;&lt;/P&gt;&lt;P&gt;So in the next step, I have created a dedicated object for port 8444 and now I can at least see, that the session timer is at 20879 sec.&lt;/P&gt;&lt;P&gt;&amp;lt;(inbound, src=[10.255.226.75,55032], dest=[10.49.2.138,8444], TCP); 20823/20879, rule=104, tcp state=TCP_ESTABLISHED, service=663, conn modules: Authentication, FG-1&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question one:&lt;/P&gt;&lt;P&gt;Does the virtual session timeout for port ranges not work?&lt;/P&gt;&lt;P&gt;Since this is matching an "any service" rule - could it be that our high port object (TCP-1024-64535) interferes here?&lt;/P&gt;&lt;P&gt;Both, the small port range and the high-ports have a "match any" flag. As per the logs, the correct object matched, though.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question two:&lt;/P&gt;&lt;P&gt;Why do I only see a session time of 20879 s in the conntab, while the time is set 86400 sec. in the port object.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 12:02:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dropped-quot-PSH-ACK-quot-Override-Session-Timeout-questions/m-p/118631#M16791</guid>
      <dc:creator>T_Sonnberger</dc:creator>
      <dc:date>2021-05-18T12:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped "PSH-ACK" / Override Session Timeout questions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dropped-quot-PSH-ACK-quot-Override-Session-Timeout-questions/m-p/118957#M16841</link>
      <description>&lt;P&gt;What version/JHF level?&lt;BR /&gt;I could see potentially needing a more specific service definition for timeouts, but the "wrong" timeout for port 8444 is definitely wrong.&lt;BR /&gt;TAC case suggested here.&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 18:02:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dropped-quot-PSH-ACK-quot-Override-Session-Timeout-questions/m-p/118957#M16841</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-20T18:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dropped "PSH-ACK" / Override Session Timeout questions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dropped-quot-PSH-ACK-quot-Override-Session-Timeout-questions/m-p/119008#M16842</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Version is 80.30 - Take 200&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding the timers, I will open a case with the support. Thanks for confirmation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 04:40:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dropped-quot-PSH-ACK-quot-Override-Session-Timeout-questions/m-p/119008#M16842</guid>
      <dc:creator>T_Sonnberger</dc:creator>
      <dc:date>2021-05-21T04:40:00Z</dc:date>
    </item>
  </channel>
</rss>

