<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FIN timer in connection table is very high in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/FIN-timer-in-connection-table-is-very-high/m-p/128270#M23418</link>
    <description>&lt;P&gt;Agree with Phoneboy here, this command wasn't even documented until I revealed it in my 2018 CPX speech and it is kind of known for having strange cosmetic issues that don't indicate an actual problem:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126573&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk126573: Incorrect output of "fw ctl conntab" when CoreXL is enabled&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Aug 2021 23:13:33 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2021-08-27T23:13:33Z</dc:date>
    <item>
      <title>FIN timer in connection table is very high</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FIN-timer-in-connection-table-is-very-high/m-p/127924#M23375</link>
      <description>&lt;P&gt;I have created several scripts with the tool "fw ctl conntab" in the last days. This shows many parameters to the connections and the timer settings of the connection. I noticed that in many versions (e.g. R80.40 JHF 120, R81 and R81.10) the FIN timers are set very high partly&amp;nbsp;&lt;STRONG&gt;approximately 10 hours&lt;/STRONG&gt;. This concerns various firewall versions.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;This means that many connections are still in the connection table with the status "DST-FIN, SRC-FIN, BOTH-FIN" for this time.&lt;/P&gt;
&lt;P&gt;According to "TCP end timeout" the values should be much lower (20 sec vs 5 sec).&lt;BR /&gt;&lt;BR /&gt;Is this a bug?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FIN_Timmer_sehr_gross.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13516i034C85F066901232/image-size/large?v=v2&amp;amp;px=999" role="button" title="FIN_Timmer_sehr_gross.JPG" alt="FIN_Timmer_sehr_gross.JPG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;On the corresponding firewalls, the timers are still set to the default values.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FIN_Timmer_sehr_gross_statefull_inspection.JPG" style="width: 745px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13517iE5E463360840C189/image-size/large?v=v2&amp;amp;px=999" role="button" title="FIN_Timmer_sehr_gross_statefull_inspection.JPG" alt="FIN_Timmer_sehr_gross_statefull_inspection.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 06:24:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FIN-timer-in-connection-table-is-very-high/m-p/127924#M23375</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2021-08-25T06:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: FIN timer in connection table is very high</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FIN-timer-in-connection-table-is-very-high/m-p/128260#M23417</link>
      <description>&lt;P&gt;I assume this would need a TAC case to dig into.&lt;BR /&gt;My feeling is this is probably a cosmetic bug of some sort.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 19:07:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FIN-timer-in-connection-table-is-very-high/m-p/128260#M23417</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-27T19:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: FIN timer in connection table is very high</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FIN-timer-in-connection-table-is-very-high/m-p/128270#M23418</link>
      <description>&lt;P&gt;Agree with Phoneboy here, this command wasn't even documented until I revealed it in my 2018 CPX speech and it is kind of known for having strange cosmetic issues that don't indicate an actual problem:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk126573&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk126573: Incorrect output of "fw ctl conntab" when CoreXL is enabled&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 23:13:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FIN-timer-in-connection-table-is-very-high/m-p/128270#M23418</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-08-27T23:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: FIN timer in connection table is very high</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FIN-timer-in-connection-table-is-very-high/m-p/131061#M23794</link>
      <description>&lt;P&gt;I am currently researching an issue and hope to get some answers.&lt;/P&gt;&lt;P&gt;Version R80.20 T160&lt;BR /&gt;Hardware: 5600 (CoreXL = 2)&lt;BR /&gt;Throughput, typically 300Mbps but sometimes there are spikes that caused interface drops and I see all RX-ERR, RX-DRP and RX-OVR for a busy interface. The overall drops are under 0.0001%.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;# fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : (100%)&lt;BR /&gt;Accelerated pkts/Total pkts : (99%)&lt;BR /&gt;F2Fed pkts/Total pkts : (0%)&lt;/P&gt;&lt;P&gt;# fwaccel stat&lt;BR /&gt;Accept Templates : disabled by Firewall&lt;BR /&gt;Layer XYZ Security disables template offloads from rule #5&lt;BR /&gt;Throughput acceleration still enabled.&lt;/P&gt;&lt;P&gt;All the high hit rules are below rule #5. Does this means that they are still getting accelerated? I have checked the top source/destination pairs in SXL table but I did not see any of these matching the high hit rules. Based on that it is hard to believe that the firewall is doing 99% acceleration?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When I run this command:&lt;BR /&gt;fwaccel conns | grep &amp;lt;IP_Address&amp;gt;&lt;/P&gt;&lt;P&gt;For most IP's I see the normal output that has mostly "established"&lt;BR /&gt;Flags are: ..N............ OR ..N......L.....&lt;/P&gt;&lt;P&gt;But for some IP addresses (from high hit rules) I only see "Both FIN"&lt;BR /&gt;What does that indicates?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 17:06:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FIN-timer-in-connection-table-is-very-high/m-p/131061#M23794</guid>
      <dc:creator>Muazzam</dc:creator>
      <dc:date>2021-10-05T17:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: FIN timer in connection table is very high</title>
      <link>https://community.checkpoint.com/t5/General-Topics/FIN-timer-in-connection-table-is-very-high/m-p/131081#M23795</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;we did run in a similar issue with R80.30 and understood following:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;TCP end timeout: A TCP connection will only terminate TCP end timeout seconds after two FIN packets (one in each direction: client-to-server, and server-to-client) or an RST packet.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;When a TCP connection ends (FIN packets sent or connection reset) the Security Gateway will keep the connection in the connections table for another TCP end timeout seconds, to allow for stray ACKs of the connection that arrive late.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 06 Oct 2021 06:41:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/FIN-timer-in-connection-table-is-very-high/m-p/131081#M23795</guid>
      <dc:creator>S_E_</dc:creator>
      <dc:date>2021-10-06T06:41:22Z</dc:date>
    </item>
  </channel>
</rss>

