Hello guys,
I have an issue with my SG, I was looking at my connections and an I found something that I think is that wrong. The webserver has too many connections like 60k, but when I use to cpview I can't see these connections When I receive an external connection on my webserver the traffic is accepted. After 1 hour my webserver tried to connect the external IP with the source port that connection was created. I have the rule to accept (Remote_Desktop_Protocol-Protocol-Signature ), but want to know why I need this rule? Did I create wrong this rule and why take 1 hour to "close" this connection?



R80.40
Jumbo Fix :119