<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Too many pending data connections for one control connection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Too-many-pending-data-connections-for-one-control-connection/m-p/27165#M2120</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am getting this Alert email and Log message after upgrading from R77.30 to R80.10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;HeaderDateHour: 28May2018 16:18:44; ContentVersion: 5; HighLevelLogKey: N/A; LogUid: N/A; SequenceNum: N/A; Action: drop; Origin: TPLCPFW1; IfDir: &amp;lt;; InterfaceName: bond28; Alert: alert; OriginSicName: CN=TPLCPFW1,O=TPLCPMGMT..er27t2; OriginSicName: CN=TPLCPFW1,O=TPLCPMGMT..er27t2; HighLevelLogKey: 18446744073709551615; src: CZO_Exchange; dst: TPIVRCTR; proto: udp; message_info: Too many pending data connections for one control connection; ProductName: VPN-1 &amp;amp; FireWall-1; svc: sip; sport_svc: sip; ProductFamily: Network;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;I have raised a case with Checkpoint TAC and they have asked me to follow the &lt;SPAN style="color: #000000; font-family: Arial; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;sk33760&lt;/SPAN&gt; every time I get this alert. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;I have gradually increased the value from 50 to 400 but still I am getting this error. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Can anyone help? Is there any other solution to this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Yash&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 May 2018 05:17:58 GMT</pubDate>
    <dc:creator>Yash_Parmar</dc:creator>
    <dc:date>2018-05-30T05:17:58Z</dc:date>
    <item>
      <title>Too many pending data connections for one control connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Too-many-pending-data-connections-for-one-control-connection/m-p/27165#M2120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am getting this Alert email and Log message after upgrading from R77.30 to R80.10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;HeaderDateHour: 28May2018 16:18:44; ContentVersion: 5; HighLevelLogKey: N/A; LogUid: N/A; SequenceNum: N/A; Action: drop; Origin: TPLCPFW1; IfDir: &amp;lt;; InterfaceName: bond28; Alert: alert; OriginSicName: CN=TPLCPFW1,O=TPLCPMGMT..er27t2; OriginSicName: CN=TPLCPFW1,O=TPLCPMGMT..er27t2; HighLevelLogKey: 18446744073709551615; src: CZO_Exchange; dst: TPIVRCTR; proto: udp; message_info: Too many pending data connections for one control connection; ProductName: VPN-1 &amp;amp; FireWall-1; svc: sip; sport_svc: sip; ProductFamily: Network;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;I have raised a case with Checkpoint TAC and they have asked me to follow the &lt;SPAN style="color: #000000; font-family: Arial; font-size: 12px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;sk33760&lt;/SPAN&gt; every time I get this alert. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;I have gradually increased the value from 50 to 400 but still I am getting this error. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Can anyone help? Is there any other solution to this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Yash&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2018 05:17:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Too-many-pending-data-connections-for-one-control-connection/m-p/27165#M2120</guid>
      <dc:creator>Yash_Parmar</dc:creator>
      <dc:date>2018-05-30T05:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Too many pending data connections for one control connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Too-many-pending-data-connections-for-one-control-connection/m-p/27166#M2121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you actually passing SIP traffic through your gateway?&lt;/P&gt;&lt;P&gt;What service is accepting the traffic in the rulebase?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Jun 2018 05:46:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Too-many-pending-data-connections-for-one-control-connection/m-p/27166#M2121</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-03T05:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Too many pending data connections for one control connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Too-many-pending-data-connections-for-one-control-connection/m-p/27167#M2122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;line-height:18.0pt;"&gt;&lt;SPAN style="font-family: inherit ,serif;mso-bidi-font-family: Segoe UI;"&gt;Are you actually passing SIP traffic through your gateway?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;line-height:18.0pt;"&gt;&lt;SPAN style="font-family: inherit ,serif;mso-bidi-font-family: Segoe UI;"&gt;What service is accepting the traffic in the &lt;SPAN&gt;rulebase&lt;/SPAN&gt;?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="width:191.0pt;margin-left:-.15pt;border-collapse:collapse;mso-yfti-tbllook:1184;mso-padding-alt:0in 5.4pt 0in 5.4pt;" width="255"&gt;&lt;TBODY&gt;&lt;TR style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:15.0pt;"&gt;&lt;TD nowrap="" style="width:59.0pt;border:solid windowtext 1.0pt;mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt;height:15.0pt;" valign="bottom" width="79"&gt;&lt;P&gt;&lt;SPAN style="mso-ascii-font-family:Calibri;mso-fareast-font-family: Times New Roman ;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri;color:black;mso-bidi-language:GU;"&gt;Name&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="" style="width:26.0pt;border:solid windowtext 1.0pt;border-left:none;mso-border-top-alt:solid windowtext .5pt;mso-border-bottom-alt:solid windowtext .5pt;mso-border-right-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt;height:15.0pt;" valign="bottom" width="35"&gt;&lt;P&gt;&lt;SPAN style="mso-ascii-font-family:Calibri;mso-fareast-font-family: Times New Roman ;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri;color:black;mso-bidi-language:GU;"&gt;Port&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="" style="width:106.0pt;border:solid windowtext 1.0pt;border-left:none;mso-border-top-alt:solid windowtext .5pt;mso-border-bottom-alt:solid windowtext .5pt;mso-border-right-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt;height:15.0pt;" valign="bottom" width="141"&gt;&lt;P&gt;&lt;SPAN style="mso-ascii-font-family:Calibri;mso-fareast-font-family: Times New Roman ;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri;color:black;mso-bidi-language:GU;"&gt;Protocol&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow:1;height:15.0pt;"&gt;&lt;TD nowrap="" style="width:59.0pt;border:solid windowtext 1.0pt;border-top:none;mso-border-left-alt:solid windowtext .5pt;mso-border-bottom-alt:solid windowtext .5pt;mso-border-right-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt;height:15.0pt;" valign="bottom" width="79"&gt;&lt;P&gt;&lt;SPAN style="mso-ascii-font-family:Calibri;mso-fareast-font-family: Times New Roman ;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri;color:black;mso-bidi-language:GU;"&gt;sip-&lt;SPAN&gt;tcp&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="" style="width:26.0pt;border-top:none;border-left:none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;mso-border-right-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt;height:15.0pt;" valign="bottom" width="35"&gt;&lt;P align="right" style="text-align:right;"&gt;&lt;SPAN style="mso-ascii-font-family:Calibri;mso-fareast-font-family: Times New Roman ;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri;color:black;mso-bidi-language:GU;"&gt;5060&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="" style="width:106.0pt;border-top:none;border-left:none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;mso-border-right-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt;height:15.0pt;" valign="bottom" width="141"&gt;&lt;P&gt;&lt;SPAN style="mso-ascii-font-family:Calibri;mso-fareast-font-family: Times New Roman ;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri;color:black;mso-bidi-language:GU;"&gt;SIP_TCP_PROTO&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow:2;height:15.0pt;"&gt;&lt;TD nowrap="" style="width:59.0pt;border:solid windowtext 1.0pt;border-top:none;mso-border-left-alt:solid windowtext .5pt;mso-border-bottom-alt:solid windowtext .5pt;mso-border-right-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt;height:15.0pt;" valign="bottom" width="79"&gt;&lt;P&gt;&lt;SPAN style="mso-fareast-font-family: Times New Roman; mso-bidi-font-family: Calibri; color: black; mso-hansi-font-family: Calibri; mso-bidi-language: GU; mso-ascii-font-family: Calibri;"&gt;sip_any&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="" style="width:26.0pt;border-top:none;border-left:none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;mso-border-right-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt;height:15.0pt;" valign="bottom" width="35"&gt;&lt;P align="right" style="text-align:right;"&gt;&lt;SPAN style="mso-ascii-font-family:Calibri;mso-fareast-font-family: Times New Roman ;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri;color:black;mso-bidi-language:GU;"&gt;5060&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="" style="width:106.0pt;border-top:none;border-left:none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;mso-border-right-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt;height:15.0pt;" valign="bottom" width="141"&gt;&lt;P&gt;&lt;SPAN style="mso-ascii-font-family:Calibri;mso-fareast-font-family: Times New Roman ;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri;color:black;mso-bidi-language:GU;"&gt;SIP_UDP_ANY&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow:3;mso-yfti-lastrow:yes;height:15.0pt;"&gt;&lt;TD nowrap="" style="width:59.0pt;border:solid windowtext 1.0pt;border-top:none;mso-border-left-alt:solid windowtext .5pt;mso-border-bottom-alt:solid windowtext .5pt;mso-border-right-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt;height:15.0pt;" valign="bottom" width="79"&gt;&lt;P&gt;&lt;SPAN style="mso-fareast-font-family: Times New Roman; mso-bidi-font-family: Calibri; color: black; mso-hansi-font-family: Calibri; mso-bidi-language: GU; mso-ascii-font-family: Calibri;"&gt;sip_any-tcp&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="" style="width:26.0pt;border-top:none;border-left:none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;mso-border-right-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt;height:15.0pt;" valign="bottom" width="35"&gt;&lt;P align="right" style="text-align:right;"&gt;&lt;SPAN style="mso-ascii-font-family:Calibri;mso-fareast-font-family: Times New Roman ;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri;color:black;mso-bidi-language:GU;"&gt;5060&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD nowrap="" style="width:106.0pt;border-top:none;border-left:none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;mso-border-bottom-alt:solid windowtext .5pt;mso-border-right-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt;height:15.0pt;" valign="bottom" width="141"&gt;&lt;P&gt;&lt;SPAN style="mso-ascii-font-family:Calibri;mso-fareast-font-family: Times New Roman ;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri;color:black;mso-bidi-language:GU;"&gt;SIP_ANY_TCP_PROTO&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Yash&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jun 2018 05:33:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Too-many-pending-data-connections-for-one-control-connection/m-p/27167#M2122</guid>
      <dc:creator>Yash_Parmar</dc:creator>
      <dc:date>2018-06-04T05:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Too many pending data connections for one control connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Too-many-pending-data-connections-for-one-control-connection/m-p/27168#M2123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, you're using the default handlers, which is a good starting point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We limit the number of pending control connections to reduce the risk of a potential denial of service.&lt;/P&gt;&lt;P&gt;At a default of 50, this limit is set pretty low out-of-the box.&amp;nbsp;&lt;/P&gt;&lt;P&gt;At 400, you are well below the max limit of 25,000 (as documented in SK).&lt;/P&gt;&lt;P&gt;As such, I'd keep increasing it as mentioned in the SK.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jun 2018 13:14:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Too-many-pending-data-connections-for-one-control-connection/m-p/27168#M2123</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-04T13:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Too many pending data connections for one control connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Too-many-pending-data-connections-for-one-control-connection/m-p/50463#M3742</link>
      <description>&lt;P&gt;Is there a way to monitor these&amp;nbsp;&lt;SPAN&gt;pending control connections?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Seeing a similar issue where we increased gradually as documented in the SK, without seeing improvement. We then increased to 5,000 and have not seen the issue since, however we are looking to see where we are at with these connections.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 15:51:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Too-many-pending-data-connections-for-one-control-connection/m-p/50463#M3742</guid>
      <dc:creator>cwilliams</dc:creator>
      <dc:date>2019-04-10T15:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Too many pending data connections for one control connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Too-many-pending-data-connections-for-one-control-connection/m-p/69826#M5372</link>
      <description>&lt;P&gt;I too have the same question, how do I find&amp;nbsp; the current state once increased&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 00:55:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Too-many-pending-data-connections-for-one-control-connection/m-p/69826#M5372</guid>
      <dc:creator>VENKAT_S_P</dc:creator>
      <dc:date>2019-12-10T00:55:31Z</dc:date>
    </item>
  </channel>
</rss>

