Re: Stateful connections dropping out after 1 minute?

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



On Jun 21, 4:26 pm, Andrew.Fu...@xxxxxxxxx wrote:
The problem itself is easy to reproduce:

* open an command prompt
* telnet to a server on the LAN (of which we have several, we use a
telnet-based thin client for our core business)
* login to the server
* press Enter or something to cause some activity, and start a
stopwatch at the same time
* roughly one minute and one second later, press some other key
* the connection has stopped updating and will drop out in a few
seconds

The telnet session is still active on the server as if nothing had
happened, but of course there's no way to get to it so it's useless.

[snip]

OK, I've finally managed to narrow it down - the dropping itself is
being caused by CheckPoint SecuRemote VPN software (one of the VPNs
mentioned), and specifically if the Windows service that accompanies
it is not running. (We stop the service by default since it blocks
traffic in private IP ranges, which messes up other aspects of our
networking).

The tricky part is that it's only triggered when switching to another
network (via DHCP at least) with a different IP range. The problem
occurs if:

* the machine is changed on-the-fly (within the one Windows session);
or
* the machine is changed during hibernation (hibernate while on one
network, resume when you've connected to another); or
* the machine is changed across reboots (shut down cleanly on one
network, boot from scratch on another).

All of these will cause the problem to appear (the last one in
particular seems really odd). However, if you plug into the new
network while the machine is up (or has just been booted), *shut
down*, and then boot up again while still on that network, the problem
goes away. There seems to be something in the shutdown process that
Checkpoint flushes.

Another workaround (apart from uninstalling Checkpoint) is to turn off
the "Checkpoint SecuRemote" item on the network adapter itself - but
then Checkpoint doesn't work, so that's not really acceptable either.

I'm going to follow up with the client who use Checkpoint, and
possibly go to the developers themselves, to see if one or the other
of the problems can be sorted out.

Regards,
Andrew

.



Relevant Pages

  • Re: Nokia IP330 / Checkpoing NG
    ... > have any network related performance problems to the monitoring server. ... > Switch, Switch to Checkpoint, Checkpoint to router or anywhere else on ...
    (comp.security.firewalls)
  • Nokia IP330 / Checkpoing NG
    ... have any network related performance problems to the monitoring server. ... Switch, Switch to Checkpoint, Checkpoint to router or anywhere else on ...
    (comp.security.firewalls)
  • Re: Exch2k3 drops remote connection attempts
    ... network telnet is working as it should be. ... If you connect from the internet ... to the smtp port than the server drops the connection. ...
    (microsoft.public.exchange.admin)
  • Re: Multiple PCs for one user?
    ... 192.168.0.* network? ... I don't see a reason to use telnet anymore, ... seperate k6 or P-one box running ip-masq as a firewall. ... server above for X processes I leave up 24/7. ...
    (Debian-User)
  • Re: Incoming Mail fails
    ... I have just tried telnet from the internal network and this works fine. ... Port 25 to the internal IP of the mail server. ...
    (microsoft.public.exchange.connectivity)