Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


Re: [VPN] Application timeouts over VPN...HELP!
.

  • To: [EMAIL PROTECTED]
  • Subject: Re: [VPN] Application timeouts over VPN...HELP!
  • From: Alex Pankratov <[EMAIL PROTECTED]>
  • Date: Sun, 13 Apr 2003 01:14:31 -0700
  • In-reply-to: <[EMAIL PROTECTED]>
  • References: <[EMAIL PROTECTED]> <[EMAIL PROTECTED]> <[EMAIL PROTECTED]> <[EMAIL PROTECTED]> <[EMAIL PROTECTED]>
  • Sender: [EMAIL PROTECTED]
.
 


Dana J. Dawson wrote:
 > You make it sound as it's a commonly accepted fact . Well, it's not.
 > There is nothing wrong with 'abnormally' Long/short TCP sessions.
 > Consider SSH, IMAP, PPTP and multitude of instant messaging protocols
 > as few examples.

There may be nothing wrong with "abnormally long" TCP sessions from a TCP or a security standpoint (I'm ignoring the concept of an "abnormally short" TCP session, since I don't believe such a thing exists), but when devices that track the states of those sessions are involved, such as firewalls, then there are very real issues that could be considered problems. Such devices have to allocate resources for each connection, so they must impose an idle timeout of some sort or risk eventual failure due to lack of resources.

Not really. Timing out idle connections is neither neccessary nor sufficient to resolve and/or prevent resource exhaustion. If the firewall does encounter the lack of resources it'd be more reasonable to drop least recently active connection, but timing it out 'preventively' serves no clear purpose. Idle TCP timeouts is more as a functional feature rather than an implementation caveat.

_______________________________________________
VPN mailing list
[EMAIL PROTECTED]
http://lists.shmoo.com/mailman/listinfo/vpn

 
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.