Endpoint Protection

 View Only
Expand all | Collapse all

SEP Network threat protection closing idle connections - Keep-Alive

Migration User

Migration UserJan 25, 2011 07:17 AM

Migration User

Migration UserJan 26, 2011 10:15 AM

Migration User

Migration UserJan 27, 2011 04:22 AM

  • 1.  SEP Network threat protection closing idle connections - Keep-Alive

    Posted Jan 25, 2011 06:16 AM

    Hi all.

     

    I have a problem whereby Network Threat Protection is closing down idle sessions (5 mintues) on certain applications  - 1 in particular is particulary noticeable

     

    I found this document that describes the problem

     

    http://www.symantec.com/business/support/index?page=content&id=TECH94334&key=55359&actp=LIST

     

    Is there anyway to stop Network Threat Protection closing down the connections as this causing massive problems with an application we use. The link above states the following

     

    To prevent idle sessions from expiring prematurely from the state table you can implement the use of TCP Keep-alive packets with an interval of less than 5 minutes

    I'm guessing this is reffering to set a keep alive within the application somehow? If so that's not really a fix as we are effected by several applications

     

    Can anyone help?

     

    Many thanks.



  • 2.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Jan 25, 2011 06:38 AM

    Hi,

     

    I think the Document refers to the setting in SEPM-Firewall Policy.

     

    Go to SEPM-Policies-Firewall Policy( Network Threat Protection), and do the setting mentioned.



  • 3.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Jan 25, 2011 07:17 AM

    Hi.

     

    There is no setting there for Keep-alives



  • 4.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Jan 26, 2011 10:15 AM

    Bump - anyone?



  • 5.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Jan 27, 2011 04:22 AM

    Really, no one?



  • 6.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Feb 01, 2011 07:28 AM

    well, no response from symantec support when I've looged this call - typical, but par for course

     

    Was hoping someone on the forums would help....?



  • 7.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Feb 01, 2011 07:41 AM

    do you see any logs on the client side?

    r u on RU6 MP2, >> ??I remember one old discussion on keep alive issues, let me search that for u ..



  • 8.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Feb 01, 2011 07:46 AM

    Hi Rafeeq.

     

    Thanks for your response

     

    no, unfortunately nothing in the logs....it's not a rule based problem - it's exactly the problem described in the link in my first post....seems that SPI part of the firewall closes the connection after 5 mintues....

    i've spoken with the software vendor but they don't employ the use of keep-alives in their product - and nor do they have to according to the RFC standards.

    It also effects our RDP connections although not a massive problem

     

    cheers



  • 9.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Feb 01, 2011 07:54 AM

    You are right, its somehow hardcoded, not sure if we can change this in registry....

    on how many servers do u want it to disable just keep  alives?



  • 10.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Feb 01, 2011 08:20 AM

    sorry - on how many servers?

    I just want my laptops/desktops to not be affected by this.....

     

    the document references changing keep alives but doesn't specify where this is done  - or if it's even a symantec change anyway....

     

    I just want it to not drop the stateful part of the connection after 5 minutes....

     

    cheers



  • 11.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Feb 01, 2011 08:26 AM

    yeah thats how it works, u can change the value  to a higher value.

    http://technet.microsoft.com/en-us/library/dd349797(WS.10).aspx



  • 12.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Feb 01, 2011 08:27 AM

    I'm surprised support didn't help...likely because you are dealing with first level. Talk to your SE and get it escalated to back line support/engineers.



  • 13.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Feb 01, 2011 08:39 AM

    thanks - I had seen that but was reluctant to change the settings as it's not really a fix....the Symantec document doesn't refer to Microsofts keep alive

     

    you think this is what needs to be changed? looking at another document for Windows XP settings it says the following

     

    KeepAliveInterval

    Key: Tcpip\Parameters
    Value Type: REG_DWORD - Time in milliseconds
    Valid Range: 1 - 0xFFFFFFFF
    Default: 1000 (one second)
    Description: This parameter determines the interval that separates keepalive retransmissions until a response is received. After a response is received, KeepAliveTime again controls the delay until the next keepalive transmission. The connection is aborted after the number of retransmissions that are specified by TcpMaxDataRetransmissions are unanswered.

    KeepAliveTime

    Key: Tcpip\Parameters
    Value Type: REG_DWORD - Time in milliseconds
    Valid Range: 1 - 0xFFFFFFFF
    Default: 7,200,000 (two hours)
    Description: The parameter controls how frequently TCP tries to verify that an idle connection is still intact by sending a keepalive packet. If the remote computer is still reachable and functioning, the remote computer acknowledges the keepalive transmission. By default, keepalive packets are not sent. A program can turn on this feature on a connection.


  • 14.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Feb 01, 2011 08:48 AM

    yes u can change that 5mins 3000 secs to a higher value.



  • 15.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Feb 01, 2011 09:20 AM

    Hi, thanks very much

    just checking it now with a registry change....although i don't fancy rolling this out

     

    Still - I shouldn't have to do this, i'm sure other firewall products don't suffer this problem.

     

    I'll let you know how I get on with this

     

    cheers



  • 16.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Feb 01, 2011 09:49 AM

    hmmmm registry change has made no difference to my machine for RDP sessions - i set it to 2.5 mins.....session still times out after 5 mins.....

     

    I'll check I've set it correctly



  • 17.  RE: SEP Network threat protection closing idle connections - Keep-Alive

    Posted Feb 03, 2011 04:02 AM

    Just to confirm - that registry setting did not work :-(