<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: time_wait in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/time-wait/m-p/7396#M891</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it is 20 seconds after the second FIN.&amp;nbsp; If a FIN is only seen from one side of the connection the TCP Session Timeout still applies.&amp;nbsp; If you have IPS Aggressive Aging enabled the various TCP session timeouts (including the TCP end timeout) can be dynamically shortened if the gateway is under heavy load.&amp;nbsp; Also if SecureXL is enabled, it adds 5 seconds to the TCP end timeout to allow time for notifications to propagate between the acceleration layer and F2F.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A class="" href="http://maxpowerfirewalls.com" rel="nofollow"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Oct 2017 14:35:14 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2017-10-11T14:35:14Z</dc:date>
    <item>
      <title>time_wait</title>
      <link>https://community.checkpoint.com/t5/General-Topics/time-wait/m-p/7393#M888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am thinking of changing time_wait value from 120 secs to 60secs at a proxy server.&lt;/P&gt;&lt;P&gt;I was wondering&amp;nbsp; of the implications of this change at our checkpoint gaia firewalls.&lt;/P&gt;&lt;P&gt;I have not been able to see if the checkpoint gaia has any setting configured for the time_wait.&lt;/P&gt;&lt;P&gt;As far as I can see at sk41248, checkpoint firewalls will close the session&amp;nbsp; 20 secs after receiving two FIN or a RST packet.&lt;/P&gt;&lt;P&gt;Is this correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Oct 2017 09:37:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/time-wait/m-p/7393#M888</guid>
      <dc:creator>Luis_Miguel_Mig</dc:creator>
      <dc:date>2017-10-11T09:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: time_wait</title>
      <link>https://community.checkpoint.com/t5/General-Topics/time-wait/m-p/7394#M889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Edit: Removed paragraph discussing increasing time_wait after misreading initial post.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The equivalent timer on the Check Point firewall is the "TCP end timeout" in the Global Properties and I would not recommend increasing it beyond the default 20 seconds, unless you are being absolutely inundated with "TCP out of state" logs sporting FIN or RST flags.&amp;nbsp; Even then some more investigation is necessary to figure out the root cause of those logs, and increasing the TCP end timeout should be a last resort.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A href="http://maxpowerfirewalls.com" target="_blank"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Oct 2017 14:20:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/time-wait/m-p/7394#M889</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-10-11T14:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: time_wait</title>
      <link>https://community.checkpoint.com/t5/General-Topics/time-wait/m-p/7395#M890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt; I think there was a misunderstanding there.&amp;nbsp; The idea is to change it from 120 to 60. 120 secs is the default value on a bluecoat proxysg.&amp;nbsp; The idea is to end up with 30 secs, but I will start changing it to 60 secs.&lt;/P&gt;&lt;P&gt;Ok, cool. 20 secs. But it is actually 20 secs after the second FIN, not the first one, right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Oct 2017 14:29:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/time-wait/m-p/7395#M890</guid>
      <dc:creator>Luis_Miguel_Mig</dc:creator>
      <dc:date>2017-10-11T14:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: time_wait</title>
      <link>https://community.checkpoint.com/t5/General-Topics/time-wait/m-p/7396#M891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it is 20 seconds after the second FIN.&amp;nbsp; If a FIN is only seen from one side of the connection the TCP Session Timeout still applies.&amp;nbsp; If you have IPS Aggressive Aging enabled the various TCP session timeouts (including the TCP end timeout) can be dynamically shortened if the gateway is under heavy load.&amp;nbsp; Also if SecureXL is enabled, it adds 5 seconds to the TCP end timeout to allow time for notifications to propagate between the acceleration layer and F2F.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A class="" href="http://maxpowerfirewalls.com" rel="nofollow"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Oct 2017 14:35:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/time-wait/m-p/7396#M891</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-10-11T14:35:14Z</dc:date>
    </item>
  </channel>
</rss>

