LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-04-2022, 07:49 AM   #1
dalacor
Member
 
Registered: Feb 2019
Distribution: Slackware
Posts: 170

Rep: Reputation: Disabled
How to determine default Iptables established connection timeouts


We are seeing a lot of dropped ACK PSH connections from Mail serer back to activesync client devices on source port 443.

The mail server provider says the Activesync timeouts are 120 secs minimum (2 mins) and 2700 secs max (45 mins).

I presume that the firewall is closing established connections long before 45 mins?

How can I find out what the min and max idle timeouts are for iptables. I use m state established, related. Haven't got around to updating the ruleset to use conntrack.
 
Old 10-04-2022, 09:47 AM   #2
elgrandeperro
Member
 
Registered: Apr 2021
Posts: 415
Blog Entries: 2

Rep: Reputation: Disabled
Its not part of iptables. Its probably a sysctl setting that you can set in /etc/sysctl.conf.

The options are probably /proc/sys/net/ipv4, but what settings to tweak you have to research that because there are timers for many tcp states.
 
Old 10-04-2022, 10:19 AM   #3
dalacor
Member
 
Registered: Feb 2019
Distribution: Slackware
Posts: 170

Original Poster
Rep: Reputation: Disabled
Thank you for that. I think that I have found the settings that I need to look at. The sysctl.conf file doesn't exist, but I can see that I need to create the file and add the necessary settings as the file is only meant to be used to change default Linux settings.

Looks like the Established timeout is 5 days, so obviously this is not the problem. Maybe the last_ack is the problem.

The section that needs to be looked at is net.netfilter.nf_conntrack_tcp_timeout
 
Old 01-24-2023, 04:56 AM   #4
dalacor
Member
 
Registered: Feb 2019
Distribution: Slackware
Posts: 170

Original Poster
Rep: Reputation: Disabled
I am marking this as solved as the issue seems to have fixed itself. I have a feeling that an IOS update fixed the issue as the problem suddenly stopped on the 13th December and has not recurred since. So it would seem that it was not a firewall issue but some IOS issue as I cannot see anything else that could have resulted in the change.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Iptables established connection jaksis Linux - Networking 3 09-26-2013 05:47 AM
iptables to drop packets from an established connection o2cool Linux - Networking 2 09-04-2012 09:43 AM
How to disconnect established connection in IPTables SlowCoder Linux - Security 8 07-02-2007 09:23 AM
Time out in Connection established state if no Data flows on that connection asurya Linux - Networking 2 04-10-2005 03:54 PM
Linksys WPC11 v2.5/SUSE 9.2 default/No connection established Linuxrat SUSE / openSUSE 1 01-24-2005 10:07 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:30 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration