Sonicwall resetting connections (For no apparent reason)

10,850

If you read the document that Evan referenced in his post you'll see that one of the components that will issue a reset is in fact, a Cache Cleanup function related to expired connection timers. This is the "idle session" clean up that I'm referring to. That's my bet as to the cause of the problem.

Share:
10,850

Related videos on Youtube

Josh Brower
Author by

Josh Brower

Information Security. SANS GSE #143. Course author of LearnOsquery.com. Lover of History & Coffee.

Updated on September 17, 2022

Comments

  • Josh Brower
    Josh Brower over 1 year

    We have a Sonicwall Pro 3060 that is transparently bridging traffic to the Internet and a VPN to another site. We are having connections being reset for no apparent reason. For instance, connecting Outlook to our Exchange server at the other site. Once every 2-3 minhutes on average, the connection is being reset, and Outlook looses connectivity. Through packet captures, I have confirmed that the Sonicwall is generating a reset packet, and sending it to the client, as if coming from the exchange server.

    We have gone through everything we can think of, and have so far come up with nothing.

    Any thoughts on why the sonicwall would be doing this?

    Josh

    • Admin
      Admin over 14 years
      How are you determining from the packet captures that the Sonicwall is issuing the reset? Also, does the Sonicwall have an "idle session" timer that might be kicking in and sending the reset?
    • Admin
      Admin over 14 years
      The Sonicwall has a built in packet capture utility, which also says whether or not it was denied, consumed, forwarded, or generated. The reset packet was "generated."
    • Admin
      Admin over 14 years
      OK, how about an idle session timer?
    • Admin
      Admin over 14 years
      @ Womble: Yes, well, it is an EOL device, with no support contract, for a non-profit. In other words, no Sonicwall support. As for idle session timer, I am not seeing an option for it.
    • Admin
      Admin over 14 years
      How about a public user forum, have you looked for one? AFAIK, all firewalls have some mechanism for dealing with idle sessions, otherwise they'd eventually run out of resources (especially memory) to handle new and established sessions.