Hello guys,
I have an issue with my SG, I was looking at my connections and an I found something that I think is that wrong. The webserver has too many connections like 60k, but when I use to cpview I can't see these connections When I receive an external connection on my webserver the traffic is accepted. After 1 hour my webserver tried to connect the external IP with the source port that connection was created. I have the rule to accept (Remote_Desktop_Protocol-Protocol-Signature ), but want to know why I need this rule? Did I create wrong this rule and why take 1 hour to "close" this connection?
![3.png 3.png](https://community.checkpoint.com/t5/image/serverpage/image-id/12803iC845E4702E7EC9AC/image-size/large?v=v2&px=999)
![Sem título.png Sem título.png](https://community.checkpoint.com/t5/image/serverpage/image-id/12801i23470415CF478ED4/image-size/large?v=v2&px=999)
![2.png 2.png](https://community.checkpoint.com/t5/image/serverpage/image-id/12818iCDEB23A0D39EDB99/image-size/large?v=v2&px=999)
R80.40
Jumbo Fix :119