<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP Connection drops after a while on a IBM AS/400 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-Connection-drops-after-a-while-on-a-IBM-AS-400/m-p/142627#M22077</link>
    <description>&lt;P&gt;As Chris said this is probably related to the VPN more than the basic session timeouts, but try enabling TCP state logging to obtain more details about how and why your telnet connections are being terminated:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101221&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk101221: TCP state logging&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Is there some particular reason you are not synchronizing the telnet sessions across the cluster members?&amp;nbsp; If deployed as shown in your screenshot a failover will cause all of the currently open telnet sessions to be killed on the newly active member.&lt;/P&gt;
&lt;P&gt;Also note that the TCP connection timeout can now be increased well beyond 86400 seconds if you have the latest Jumbo HFA:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk168872&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk168872: Virtual session timeout for a TCP Service (86400 seconds) is not long enough for a specific TCP service&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Feb 2022 13:41:27 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2022-02-28T13:41:27Z</dc:date>
    <item>
      <title>TCP Connection drops after a while on a IBM AS/400</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-Connection-drops-after-a-while-on-a-IBM-AS-400/m-p/142588#M22066</link>
      <description>&lt;P&gt;We have an issue regarding a specific connection on a S2S VPN between a CP cluster and Cisco ASA.&lt;BR /&gt;Specifically, whilst the tunnel poses no issues and everything seems to be fine, an IBM AS/400 server is behind the CP and the clients accessing it are behind the ASA.&lt;BR /&gt;The clients complain that the sessions all of a sudden close after an arbitrary amount of time.&lt;BR /&gt;I have proceeded with creating a new telnet service with the following characteristics, but the issue seems to still occur.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="new_telnet.png" style="width: 516px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15530iFEF9497B74597136/image-dimensions/516x566?v=v2" width="516" height="566" role="button" title="new_telnet.png" alt="new_telnet.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any ideas ?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 08:03:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-Connection-drops-after-a-while-on-a-IBM-AS-400/m-p/142588#M22066</guid>
      <dc:creator>Nikolaos_Liakop</dc:creator>
      <dc:date>2022-02-28T08:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Connection drops after a while on a IBM AS/400</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-Connection-drops-after-a-while-on-a-IBM-AS-400/m-p/142592#M22067</link>
      <description>&lt;P&gt;Check your IPS if you run it and core protections. I had AS/400 connections blocked because Telnet is considered insecure and blocked by this blade and needed to configure exceptions.&lt;/P&gt;&lt;P&gt;Also, there's obviously the ASA side which might not match your protocol definitions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 08:29:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-Connection-drops-after-a-while-on-a-IBM-AS-400/m-p/142592#M22067</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2022-02-28T08:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Connection drops after a while on a IBM AS/400</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-Connection-drops-after-a-while-on-a-IBM-AS-400/m-p/142604#M22071</link>
      <description>&lt;P&gt;It is not an IPS issue.&lt;/P&gt;&lt;P&gt;The connection gets established.&lt;/P&gt;&lt;P&gt;However after some arbitrary time the connections gets droppped and they need to relogin...&lt;/P&gt;&lt;P&gt;Protocol is telnet&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 10:36:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-Connection-drops-after-a-while-on-a-IBM-AS-400/m-p/142604#M22071</guid>
      <dc:creator>Nikolaos_Liakop</dc:creator>
      <dc:date>2022-02-28T10:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Connection drops after a while on a IBM AS/400</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-Connection-drops-after-a-while-on-a-IBM-AS-400/m-p/142619#M22075</link>
      <description>&lt;P&gt;Arbitrary like when the firewall policy is installed or when a rekey occurs for the VPN?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 12:56:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-Connection-drops-after-a-while-on-a-IBM-AS-400/m-p/142619#M22075</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-28T12:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Connection drops after a while on a IBM AS/400</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-Connection-drops-after-a-while-on-a-IBM-AS-400/m-p/142627#M22077</link>
      <description>&lt;P&gt;As Chris said this is probably related to the VPN more than the basic session timeouts, but try enabling TCP state logging to obtain more details about how and why your telnet connections are being terminated:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101221&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk101221: TCP state logging&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Is there some particular reason you are not synchronizing the telnet sessions across the cluster members?&amp;nbsp; If deployed as shown in your screenshot a failover will cause all of the currently open telnet sessions to be killed on the newly active member.&lt;/P&gt;
&lt;P&gt;Also note that the TCP connection timeout can now be increased well beyond 86400 seconds if you have the latest Jumbo HFA:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk168872&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk168872: Virtual session timeout for a TCP Service (86400 seconds) is not long enough for a specific TCP service&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 13:41:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/TCP-Connection-drops-after-a-while-on-a-IBM-AS-400/m-p/142627#M22077</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-02-28T13:41:27Z</dc:date>
    </item>
  </channel>
</rss>

