<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: outlook imap connections broken in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64268#M2440</link>
    <description>&lt;P&gt;Unfortunatelly extended to 120 seconds IMAPS sessions timeout doesn't do the job.&lt;/P&gt;&lt;P&gt;Do you know any other parameters to tune up or maybe some blades to switch off?&lt;/P&gt;&lt;P&gt;Or should I call TAC directly?&lt;/P&gt;</description>
    <pubDate>Thu, 03 Oct 2019 07:32:35 GMT</pubDate>
    <dc:creator>RtoipIkswelisaw</dc:creator>
    <dc:date>2019-10-03T07:32:35Z</dc:date>
    <item>
      <title>outlook imap connections broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/63571#M2400</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I am not quite sure if it is even problem od my 790 appliances, but it happens only in our offices. Every so often Outlook IMAP connections get blocked on sending / receiving emails. When it happens, progress bar freezes in half. After that I cannot close Outlook in ordinary way and I have to do it by task manager killing process. Next start everything works correct but only until next stop.&lt;/P&gt;&lt;P&gt;It started many months ago, but first I thought it will go with next MS Office update. Time is running out and still many different versions of Outlook perform not better.&lt;/P&gt;&lt;P&gt;This does not happens outside office, not on every station but in all offices where we have 7x0 appliances.&lt;/P&gt;&lt;P&gt;Our mail server is hosted by ISP.&lt;/P&gt;&lt;P&gt;I have IPS, Anti-Virus, Anti-Bot and &lt;SPAN&gt;Applications &amp;amp; URL Filtering&amp;nbsp;&lt;/SPAN&gt;activated while Anti-Spam, Threat Emulation, QoS not and SSL Inspection set to HTTPS Categorization. I have also standard policy set on FW and other blades. I block&amp;nbsp;&lt;SPAN class="cp-label-link-container "&gt;security risk categories and "&lt;SPAN class="appi-activation-groups-link "&gt;other undesired applications".&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cp-label-link-container "&gt;&lt;SPAN class="appi-activation-groups-link "&gt;Does anyone suffers from similar problem and knows solution, please?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 14:30:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/63571#M2400</guid>
      <dc:creator>RtoipIkswelisaw</dc:creator>
      <dc:date>2019-09-24T14:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: outlook imap connections broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/63689#M2409</link>
      <description>What do your Security Logs say when these issues are happening?</description>
      <pubDate>Wed, 25 Sep 2019 20:25:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/63689#M2409</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-25T20:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: outlook imap connections broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64101#M2424</link>
      <description>&lt;P&gt;Sorry for the delay but i tried to hunt for error and corresponding logs. No luck. I cannot find anything interesting in the logs.&lt;BR /&gt;I was looking for entries about my computer's IP and mail server IP. I found only something like:&lt;/P&gt;&lt;TABLE cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;Today 21:49:01&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;Piotr Wasilewski (pwasilewski)&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;&lt;DIV class="cp cp-glyph-url_filtering cp-icon-default-color cp-image"&gt;&amp;nbsp;&lt;/DIV&gt;URL Filtering&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;LAN1&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;&lt;DIV class="cp cp-glyph-accept cp-icon-ok-color cp-image"&gt;&amp;nbsp;&lt;/DIV&gt;Allow&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;192.168.0.121&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;79.96.193.51&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;TCP/993&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;1 (Outgoing)&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;home.pl was allowed&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;Today 21:09:00&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;Piotr Wasilewski (pwasilewski)&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;&lt;DIV class="cp cp-glyph-application_control cp-icon-default-color cp-image"&gt;&amp;nbsp;&lt;/DIV&gt;Application Control&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;WAN&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;&lt;DIV class="cp cp-glyph-accept cp-icon-ok-color cp-image"&gt;&amp;nbsp;&lt;/DIV&gt;Allow&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;192.168.0.121&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;79.96.193.51&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;TCP/993&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;1 (Outgoing)&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="x-grid-cell-inner "&gt;SSL Protocol was allowed&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;but not exactly at the time of the connection break. There is no blocked traffic between the two.&lt;BR /&gt;How can I get closer to the problem?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 20:05:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64101#M2424</guid>
      <dc:creator>RtoipIkswelisaw</dc:creator>
      <dc:date>2019-10-01T20:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: outlook imap connections broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64103#M2425</link>
      <description>&lt;P&gt;The behavior seems to be that the connection gets interrupted somehow and the client doesn't quite know how to deal with it.&lt;BR /&gt;I was thinking it could be an IPS signature that was triggering it...and that may still be happening.&lt;BR /&gt;You'd have to get some debugs from the appliance while the problem is happening to understand.&lt;BR /&gt;TAC should be able to assist with this.&lt;/P&gt;
&lt;P&gt;Another, simpler thing to try would be increasing the TCP timeout for IMAPS and possibly SMTP, depending on how your client is sending mail.&lt;BR /&gt;For most TCP services, this is usually 3600 seconds (1 hour).&lt;BR /&gt;For some reason, IMAPS has a very low timeout (like 40 seconds) and you may want to change it:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-10-01 at 1.27.15 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2676iBDD6DB2D9FDB40FA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2019-10-01 at 1.27.15 PM.png" alt="Screen Shot 2019-10-01 at 1.27.15 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 20:29:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64103#M2425</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-01T20:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: outlook imap connections broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64111#M2426</link>
      <description>&lt;P&gt;Thank you very much for hint. I take it as a suggestion to extend that time.&lt;/P&gt;&lt;P&gt;However I have already 60 seconds sessions timeout for IMAPS while 3600 for IMAP and enabled aggresive agging by default. I put 120 seconds and report back what happened. Is aggresive agging&amp;nbsp;something I should bother with?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2019 21:43:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64111#M2426</guid>
      <dc:creator>RtoipIkswelisaw</dc:creator>
      <dc:date>2019-10-01T21:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: outlook imap connections broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64115#M2427</link>
      <description>Aggressive Aging happens when the appliance is operating at close to its max connection capacity.&lt;BR /&gt;Basically, once the threshold is passed (80%, I believe), existing connections are "aggressively aged" until the number of connections is again below the threshold.&lt;BR /&gt;In general, the exact number of connections supported will depend on the amount of memory in the appliance, blades, etc.&lt;BR /&gt;However, SMB appliances do not have expandable memory.&lt;BR /&gt;In my 750, the limit is 150k.</description>
      <pubDate>Tue, 01 Oct 2019 22:27:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64115#M2427</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-01T22:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: outlook imap connections broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64268#M2440</link>
      <description>&lt;P&gt;Unfortunatelly extended to 120 seconds IMAPS sessions timeout doesn't do the job.&lt;/P&gt;&lt;P&gt;Do you know any other parameters to tune up or maybe some blades to switch off?&lt;/P&gt;&lt;P&gt;Or should I call TAC directly?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2019 07:32:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64268#M2440</guid>
      <dc:creator>RtoipIkswelisaw</dc:creator>
      <dc:date>2019-10-03T07:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: outlook imap connections broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64334#M2442</link>
      <description>Perhaps fw ctl zdebug drop | grep a.b.c.d might help you understand why packets are being dropped.&lt;BR /&gt;The TAC should be able to help as well.</description>
      <pubDate>Thu, 03 Oct 2019 23:35:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64334#M2442</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-03T23:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: outlook imap connections broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64342#M2443</link>
      <description>&lt;P&gt;Thank you very much. I will try with the command first.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2019 07:23:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/outlook-imap-connections-broken/m-p/64342#M2443</guid>
      <dc:creator>RtoipIkswelisaw</dc:creator>
      <dc:date>2019-10-04T07:23:04Z</dc:date>
    </item>
  </channel>
</rss>

