This is a discussion on Re: new client connection server thinks is already established ! within the IPFilter forums, part of the System Security and Security Related category; On Tue, 5 Feb 2008, Jefferson Ogata wrote: > It wouldn't just be for that problem; it would be ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
On Tue, 5 Feb 2008, Jefferson Ogata wrote:
> It wouldn't just be for that problem; it would be for all stale > connections. If you aren't using return-rst, every time you lose state > information because of a reboot (for example), any box that didn't get a > TCP teardown thinks it still has a live connection to the box. Using > return-rst clears that up at the next window probe. Without return-rst, > those connections end up hanging around until the keepalive timers kill > them. This is wasteful and provides no benefit. Hmm, you make a good point -- I hadn't considered the generic issue. Thanks... -- Paul B. Henson | (909) 979-6361 | http://www.csupomona.edu/~henson/ Operating Systems and Network Analyst | henson@csupomona.edu California State Polytechnic University | Pomona CA 91768 |
![]() |
| Thread Tools | |
| Display Modes | |
|
|