<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R80.20 - Port reuse problem in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Port-reuse-problem/m-p/83509#M16889</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;This is my first post here. I had read a lot of posts before that helped me several times (thank you very much!) but it’s my first time writing something.&lt;/P&gt;&lt;P&gt;I’m facing a problem with one of our customers. He’s using a Bluecoat web proxy with persistent connections to connect to an Apache web server (Linux) on our side. There is a R80.20 gateway between us.&lt;/P&gt;&lt;P&gt;Sometimes, some of the connections become idle and so, our Apache is closing them once the Apache keepalive timeout is over.&lt;/P&gt;&lt;P&gt;When it happens, the Apache server sends a FIN packet that is acknowledged by the remote web proxy. However, the proxy is not sending back its FIN packet. Therefore, the TCP/IP stack of the web server operating system ends closing the socket.&lt;/P&gt;&lt;P&gt;The problem is that in that case, the connection remains in the gateway connections table until the session timeout is over (3600 seconds).&lt;/P&gt;&lt;P&gt;If there is a new connection meanwhile from the remote web proxy using the same source port, the gateway drops it with the following message seen in debug mode: “dropped by fw_handle_old_conn_recovery Reason: TCP packet that belongs to an old connection;”.&lt;/P&gt;&lt;P&gt;I thought that Smart Connection Reuse setting (which is enabled in our gateway) would avoid that kind of situations but maybe I haven’t really understood how it works.&lt;/P&gt;&lt;P&gt;Anyone else had a similar problem ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your help.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2020 16:00:54 GMT</pubDate>
    <dc:creator>itcs</dc:creator>
    <dc:date>2020-04-28T16:00:54Z</dc:date>
    <item>
      <title>R80.20 - Port reuse problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Port-reuse-problem/m-p/83509#M16889</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;This is my first post here. I had read a lot of posts before that helped me several times (thank you very much!) but it’s my first time writing something.&lt;/P&gt;&lt;P&gt;I’m facing a problem with one of our customers. He’s using a Bluecoat web proxy with persistent connections to connect to an Apache web server (Linux) on our side. There is a R80.20 gateway between us.&lt;/P&gt;&lt;P&gt;Sometimes, some of the connections become idle and so, our Apache is closing them once the Apache keepalive timeout is over.&lt;/P&gt;&lt;P&gt;When it happens, the Apache server sends a FIN packet that is acknowledged by the remote web proxy. However, the proxy is not sending back its FIN packet. Therefore, the TCP/IP stack of the web server operating system ends closing the socket.&lt;/P&gt;&lt;P&gt;The problem is that in that case, the connection remains in the gateway connections table until the session timeout is over (3600 seconds).&lt;/P&gt;&lt;P&gt;If there is a new connection meanwhile from the remote web proxy using the same source port, the gateway drops it with the following message seen in debug mode: “dropped by fw_handle_old_conn_recovery Reason: TCP packet that belongs to an old connection;”.&lt;/P&gt;&lt;P&gt;I thought that Smart Connection Reuse setting (which is enabled in our gateway) would avoid that kind of situations but maybe I haven’t really understood how it works.&lt;/P&gt;&lt;P&gt;Anyone else had a similar problem ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your help.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 16:00:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Port-reuse-problem/m-p/83509#M16889</guid>
      <dc:creator>itcs</dc:creator>
      <dc:date>2020-04-28T16:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 - Port reuse problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Port-reuse-problem/m-p/83577#M16913</link>
      <description>&lt;P&gt;There is a kernel parameter that controls this behaviour. Look into&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk24960" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk24960&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 07:49:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Port-reuse-problem/m-p/83577#M16913</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-04-29T07:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 - Port reuse problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Port-reuse-problem/m-p/83579#M16915</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your answer.&lt;/P&gt;&lt;P&gt;This parameter was already enabled in our gateway (fwconn_smart_conn_reuse = 1) but it's not working as I would expect unless I'm misunderstanding this setting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there maybe another parameter that could be overriding that one ?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2020 08:00:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Port-reuse-problem/m-p/83579#M16915</guid>
      <dc:creator>itcs</dc:creator>
      <dc:date>2020-04-29T08:00:00Z</dc:date>
    </item>
  </channel>
</rss>

