Re: Zebedee and KEEPALIVE

Yves Smolders <[email protected]> Fri, 21 Sep 2012 11:42:53 +0200
Newsgroups gmane.comp.security.zebedee.general
Message-ID <CAMpN9EsELmcr1LjACZRLsrrWTyYvJPFkxft+w6=zSFWQffOZbg@mail.gmail.com>
--===============3181180432708422510==
Content-Type: multipart/alternative; boundary=bcaec54fb4145c653704ca3310a3

--bcaec54fb4145c653704ca3310a3
Content-Type: text/plain; charset=ISO-8859-1

Hello Vasily,

I have never experienced this kind of disconnections before.  I'm still
using zebedee in a number of places for IMAP connections which also keep
open a long time with low traffic - I haven't seen much of reconnections in
there.

Is there a possibility the issue might be in a firewall somewhere?  Some
NAT or PAT/Portmapping issue going on?  Newer firewalls with deep packet
inspection engines do the strangest things to connections,
buffering/delaying them for virusscanning, etc.

Most portmapping firewalls also have settings for timeouts on the
connections.

Regards,
Yves

On 21 September 2012 08:29, Ovchinnikov Vasily <[email protected]> wrote:

> Hi!
>
> I've been used zebedee for many years and I know that zebedee used
> SO_KEEPALIVE socket option for both client
> and server. Our network involved more than 100 servers all over the Russia
> and zebedee protects Firebird SQL
> server traffic over the public Internet connections.
>
> But time to time I stand face to face with a small problem and I cannot
> explain why it happens.
>
> When connection brokes on the client side than zebedee process that serves
> this secure channel on the server
> side don't recognize this fact and don't closes connection (both to broken
> client and to local SQL server) and
> don't terminates. Therefor SQL server resources still used also and those
> clients looks like "dead clients"
> for SQL server. Like clients with the long-long-time transaction. And
> nothing happens within this transaction.
> Restarting of zebedee server is the solution. But this set me pay
> attention for this and it's so hard to
> monitor 100+ servers continiously. Because of that I restart zebedee
> server by shcedule once-a-day on some
> servers where this problem occured more offtenly.
>
> All the servers runs Windows 2003/2008. Keepalive settings has default
> vales (keepalive time 120 min)
> Zebedee server logfile do not contains any records about unavailability of
> setting SO_KEEPALIVE socket option.
>
> I think that I have to research this situation by standing some
> experiments with network sniffer on the
> zebedee server side.
>
> Maybe someone has a solution? Or it looks like only TCP stack KEEPALIVE
> problem?
>
> --
> Regards,
> Ovchinnikov Vasily
> ova at tkvc ru
>
>
>
>
> ------------------------------------------------------------------------------
> Got visibility?
> Most devs has no idea what their production app looks like.
> Find out how fast your code is with AppDynamics Lite.
> http://ad.doubleclick.net/clk;262219671;13503038;y?
> http://info.appdynamics.com/FreeJavaPerformanceDownload.html
> _______________________________________________
> Zebedee-talk mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/zebedee-talk
>

--bcaec54fb4145c653704ca3310a3
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hello Vasily,<div><br></div><div>I have never experienced this kind of disc=
onnections before. =A0I&#39;m still using zebedee in a number of places for=
 IMAP connections which also keep open a long time with low traffic - I hav=
en&#39;t seen much of reconnections in there.</div>
<div><br></div><div>Is there a possibility the issue might be in a firewall=
 somewhere? =A0Some NAT or PAT/Portmapping issue going on? =A0Newer firewal=
ls with deep packet inspection engines do the strangest things to connectio=
ns, buffering/delaying them for virusscanning, etc.</div>
<div><br></div><div>Most portmapping firewalls also have settings for timeo=
uts on the connections.</div><div><br></div><div>Regards,</div><div>Yves<br=
><br><div class=3D"gmail_quote">On 21 September 2012 08:29, Ovchinnikov Vas=
ily <span dir=3D"ltr">&lt;<a href=3D"mailto:[email protected]" target=3D"_blank">=
[email protected]</a>&gt;</span> wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">Hi!<br>
<br>
I&#39;ve been used zebedee for many years and I know that zebedee used SO_K=
EEPALIVE socket option for both client<br>
and server. Our network involved more than 100 servers all over the Russia =
and zebedee protects Firebird SQL<br>
server traffic over the public Internet connections.<br>
<br>
But time to time I stand face to face with a small problem and I cannot exp=
lain why it happens.<br>
<br>
When connection brokes on the client side than zebedee process that serves =
this secure channel on the server<br>
side don&#39;t recognize this fact and don&#39;t closes connection (both to=
 broken client and to local SQL server) and<br>
don&#39;t terminates. Therefor SQL server resources still used also and tho=
se clients looks like &quot;dead clients&quot;<br>
for SQL server. Like clients with the long-long-time transaction. And nothi=
ng happens within this transaction.<br>
Restarting of zebedee server is the solution. But this set me pay attention=
 for this and it&#39;s so hard to<br>
monitor 100+ servers continiously. Because of that I restart zebedee server=
 by shcedule once-a-day on some<br>
servers where this problem occured more offtenly.<br>
<br>
All the servers runs Windows 2003/2008. Keepalive settings has default vale=
s (keepalive time 120 min)<br>
Zebedee server logfile do not contains any records about unavailability of =
setting SO_KEEPALIVE socket option.<br>
<br>
I think that I have to research this situation by standing some experiments=
 with network sniffer on the<br>
zebedee server side.<br>
<br>
Maybe someone has a solution? Or it looks like only TCP stack KEEPALIVE pro=
blem?<br>
<br>
--<br>
Regards,<br>
Ovchinnikov Vasily<br>
ova at tkvc ru<br>
<br>
<br>
<br>
---------------------------------------------------------------------------=
---<br>
Got visibility?<br>
Most devs has no idea what their production app looks like.<br>
Find out how fast your code is with AppDynamics Lite.<br>
<a href=3D"http://ad.doubleclick.net/clk;262219671;13503038;y" target=3D"_b=
lank">http://ad.doubleclick.net/clk;262219671;13503038;y</a>?<br>
<a href=3D"http://info.appdynamics.com/FreeJavaPerformanceDownload.html" ta=
rget=3D"_blank">http://info.appdynamics.com/FreeJavaPerformanceDownload.htm=
l</a><br>
_______________________________________________<br>
Zebedee-talk mailing list<br>
<a href=3D"mailto:[email protected]">[email protected]=
urceforge.net</a><br>
<a href=3D"https://lists.sourceforge.net/lists/listinfo/zebedee-talk" targe=
t=3D"_blank">https://lists.sourceforge.net/lists/listinfo/zebedee-talk</a><=
br>
</blockquote></div><br></div>

--bcaec54fb4145c653704ca3310a3--


--===============3181180432708422510==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------
Got visibility?
Most devs has no idea what their production app looks like.
Find out how fast your code is with AppDynamics Lite.
http://ad.doubleclick.net/clk;262219671;13503038;y?
http://info.appdynamics.com/FreeJavaPerformanceDownload.html
--===============3181180432708422510==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Zebedee-talk mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/zebedee-talk

--===============3181180432708422510==--