• Open Menu Close Menu
  • Apple
  • Shopping Bag
  • Apple
  • Mac
  • iPad
  • iPhone
  • Watch
  • TV
  • Music
  • Support
  • Search apple.com
  • Shopping Bag

Lists

Open Menu Close Menu
  • Terms and Conditions
  • Lists hosted on this site
  • Email the Postmaster
  • Tips for posting to public mailing lists
Re: TCP_KEEPALIVE
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: TCP_KEEPALIVE


  • Subject: Re: TCP_KEEPALIVE
  • From: email@hidden
  • Date: Sun, 5 Nov 2006 20:29:46 -0700


The places this doesn't hold true are:

(1)	Some place along the path, you've firewalled off ARP packets, OR

(2) You have a Cisco PiiX firewall or other stateful firewall that tracks connection state, and has a connection timeout in order to prevent a DOS attack via connection table overflow over time (in which case, it's configurable, but you are likely either failing to configure it, or you don't have rights to configure it).


You'll also see this type of behavior in any other kind of firewall that performs it's function by NAT'ing your inside IP address to an external IP address. The translation table typically has an idle timeout and will delete your NAT session after a period of inactivity. The firewalls will sometimes send RST's in both directions indicating that the connection is being closed abortively.

-Joe

_______________________________________________
Do not post admin requests to the list. They will be ignored.
Darwin-kernel mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden


References: 
 >TCP_KEEPALIVE (From: Michael Ledford <email@hidden>)
 >Re: TCP_KEEPALIVE (From: Terry Lambert <email@hidden>)

  • Prev by Date: Re: pseudo-device pty >32
  • Next by Date: XXXX is not compatible with its superclass, 13IOAudioEngine superclass changed?
  • Previous by thread: Re: TCP_KEEPALIVE
  • Next by thread: XXXX is not compatible with its superclass, 13IOAudioEngine superclass changed?
  • Index(es):
    • Date
    • Thread