Re: Zebedee and KEEPALIVE
Yves Smolders <[email protected]> Fri, 21 Sep 2012 11:42:53 +0200
| Newsgroups | gmane.comp.security.zebedee.general |
|---|---|
| Message-ID | <CAMpN9EsELmcr1LjACZRLsrrWTyYvJPFkxft+w6=zSFWQffOZbg@mail.gmail.com> |
--===============3181180432708422510== Content-Type: multipart/alternative; boundary=bcaec54fb4145c653704ca3310a3 --bcaec54fb4145c653704ca3310a3 Content-Type: text/plain; charset=ISO-8859-1 Hello Vasily, I have never experienced this kind of disconnections before. I'm still using zebedee in a number of places for IMAP connections which also keep open a long time with low traffic - I haven't seen much of reconnections in there. Is there a possibility the issue might be in a firewall somewhere? Some NAT or PAT/Portmapping issue going on? Newer firewalls with deep packet inspection engines do the strangest things to connections, buffering/delaying them for virusscanning, etc. Most portmapping firewalls also have settings for timeouts on the connections. Regards, Yves On 21 September 2012 08:29, Ovchinnikov Vasily <[email protected]> wrote: > Hi! > > I've been used zebedee for many years and I know that zebedee used > SO_KEEPALIVE socket option for both client > and server. Our network involved more than 100 servers all over the Russia > and zebedee protects Firebird SQL > server traffic over the public Internet connections. > > But time to time I stand face to face with a small problem and I cannot > explain why it happens. > > When connection brokes on the client side than zebedee process that serves > this secure channel on the server > side don't recognize this fact and don't closes connection (both to broken > client and to local SQL server) and > don't terminates. Therefor SQL server resources still used also and those > clients looks like "dead clients" > for SQL server. Like clients with the long-long-time transaction. And > nothing happens within this transaction. > Restarting of zebedee server is the solution. But this set me pay > attention for this and it's so hard to > monitor 100+ servers continiously. Because of that I restart zebedee > server by shcedule once-a-day on some > servers where this problem occured more offtenly. > > All the servers runs Windows 2003/2008. Keepalive settings has default > vales (keepalive time 120 min) > Zebedee server logfile do not contains any records about unavailability of > setting SO_KEEPALIVE socket option. > > I think that I have to research this situation by standing some > experiments with network sniffer on the > zebedee server side. > > Maybe someone has a solution? Or it looks like only TCP stack KEEPALIVE > problem? > > -- > Regards, > Ovchinnikov Vasily > ova at tkvc ru > > > > > ------------------------------------------------------------------------------ > Got visibility? > Most devs has no idea what their production app looks like. > Find out how fast your code is with AppDynamics Lite. > http://ad.doubleclick.net/clk;262219671;13503038;y? > http://info.appdynamics.com/FreeJavaPerformanceDownload.html > _______________________________________________ > Zebedee-talk mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/zebedee-talk > --bcaec54fb4145c653704ca3310a3 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Hello Vasily,<div><br></div><div>I have never experienced this kind of disc= onnections before. =A0I'm still using zebedee in a number of places for= IMAP connections which also keep open a long time with low traffic - I hav= en't seen much of reconnections in there.</div> <div><br></div><div>Is there a possibility the issue might be in a firewall= somewhere? =A0Some NAT or PAT/Portmapping issue going on? =A0Newer firewal= ls with deep packet inspection engines do the strangest things to connectio= ns, buffering/delaying them for virusscanning, etc.</div> <div><br></div><div>Most portmapping firewalls also have settings for timeo= uts on the connections.</div><div><br></div><div>Regards,</div><div>Yves<br= ><br><div class=3D"gmail_quote">On 21 September 2012 08:29, Ovchinnikov Vas= ily <span dir=3D"ltr"><<a href=3D"mailto:[email protected]" target=3D"_blank">= [email protected]</a>></span> wrote:<br> <blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p= x #ccc solid;padding-left:1ex">Hi!<br> <br> I've been used zebedee for many years and I know that zebedee used SO_K= EEPALIVE socket option for both client<br> and server. Our network involved more than 100 servers all over the Russia = and zebedee protects Firebird SQL<br> server traffic over the public Internet connections.<br> <br> But time to time I stand face to face with a small problem and I cannot exp= lain why it happens.<br> <br> When connection brokes on the client side than zebedee process that serves = this secure channel on the server<br> side don't recognize this fact and don't closes connection (both to= broken client and to local SQL server) and<br> don't terminates. Therefor SQL server resources still used also and tho= se clients looks like "dead clients"<br> for SQL server. Like clients with the long-long-time transaction. And nothi= ng happens within this transaction.<br> Restarting of zebedee server is the solution. But this set me pay attention= for this and it's so hard to<br> monitor 100+ servers continiously. Because of that I restart zebedee server= by shcedule once-a-day on some<br> servers where this problem occured more offtenly.<br> <br> All the servers runs Windows 2003/2008. Keepalive settings has default vale= s (keepalive time 120 min)<br> Zebedee server logfile do not contains any records about unavailability of = setting SO_KEEPALIVE socket option.<br> <br> I think that I have to research this situation by standing some experiments= with network sniffer on the<br> zebedee server side.<br> <br> Maybe someone has a solution? Or it looks like only TCP stack KEEPALIVE pro= blem?<br> <br> --<br> Regards,<br> Ovchinnikov Vasily<br> ova at tkvc ru<br> <br> <br> <br> ---------------------------------------------------------------------------= ---<br> Got visibility?<br> Most devs has no idea what their production app looks like.<br> Find out how fast your code is with AppDynamics Lite.<br> <a href=3D"http://ad.doubleclick.net/clk;262219671;13503038;y" target=3D"_b= lank">http://ad.doubleclick.net/clk;262219671;13503038;y</a>?<br> <a href=3D"http://info.appdynamics.com/FreeJavaPerformanceDownload.html" ta= rget=3D"_blank">http://info.appdynamics.com/FreeJavaPerformanceDownload.htm= l</a><br> _______________________________________________<br> Zebedee-talk mailing list<br> <a href=3D"mailto:[email protected]">[email protected]= urceforge.net</a><br> <a href=3D"https://lists.sourceforge.net/lists/listinfo/zebedee-talk" targe= t=3D"_blank">https://lists.sourceforge.net/lists/listinfo/zebedee-talk</a><= br> </blockquote></div><br></div> --bcaec54fb4145c653704ca3310a3-- --===============3181180432708422510== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ------------------------------------------------------------------------------ Got visibility? Most devs has no idea what their production app looks like. Find out how fast your code is with AppDynamics Lite. http://ad.doubleclick.net/clk;262219671;13503038;y? http://info.appdynamics.com/FreeJavaPerformanceDownload.html --===============3181180432708422510== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Zebedee-talk mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/zebedee-talk --===============3181180432708422510==--