Re: Zebedee and KEEPALIVE
Ovchinnikov Vasily <[email protected]> Mon, 24 Sep 2012 10:58:30 +0400
| Newsgroups | gmane.comp.security.zebedee.general |
|---|---|
| Message-ID | <[email protected]> |
Hi, Yves! Yves Smolders wrote: > > I have never experienced this kind of disconnections before. I'm still using zebedee in a number of places > for IMAP connections which also keep open a long time with low traffic - I haven't seen much of reconnections > in there. Firebird SQL has a one specific problem: SQL client-server dialogue traffic is much fragmented! Many short packets in addition to big round trip time (tested by ping) is the problem. When some TCP packets drops anywhere the connection dropped. And as worse the round trip time as more often dead client problem raises up on server. And only when connect drops within zebedee channel! When the local Firebird SQL client connection dropped than that's all seems to be all right. Local SQL-server connections doesn't use zebedee and server TCP/IP stack via keep-alive mechanism drops such connections very well. But when remote client connection dropped than server zebedee process have to close both this connection and the local SQL-server connection. I think that TCP socket should be closed by TCP/IP stack primarily using keep-alive. Than server zebedee process get know it about and closes connections both to remote zebedee client and SQL-server. I think so. But unfortunately things are not the same. And I have no ideas how to exam zebedee server behaviour when remote zebedee client drops connection. Just with network packet sniffer?.. So, I need to change keep-alive settings for server TCP/IP stack to low-time values and try to reproduce broken client connection manually (e.g. by killing remote client zebedee process) while logging TCP-packets by sniffer on the server side. > Is there a possibility the issue might be in a firewall somewhere? Some NAT or PAT/Portmapping issue going > on? Newer firewalls with deep packet inspection engines do the strangest things to connections, > buffering/delaying them for virusscanning, etc. Obligatory! All servers are behind NAT. Firewall usuially is a part of ADSL modem and has no spesial timeout or keep-alive settings. Virus scanning software "Dr.Web" used almost everywhere but it works only in the file scanning mode. > > Most portmapping firewalls also have settings for timeouts on the connections. There is no such exotic software :) Only hardware firewalls inside low-cost ADSL modems (usially D-Link(c) ). -- Regards, Ovchinnikov Vasily ova at tkvc ru ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/