Manuel Kasper <mk at neon1 dot net> wrote:
> That's because as of 1.2b2, the TCP idle timeout for the firewall is
> 2.5 hours instead of the ipfilter default of 10 days (!) to keep the
> state table from filling up with dead connections. This value can be
> modified on the advanced setup page, though it is not recommended to
> do that. So of course if your SSH connection doesn't transfer a
> single byte for two hours, the ipfilter state table entry is deleted
> and the connection breaks. Try turning on keep-alive in your SSH
> client.
This needs to go into the documentation or the FAQ. Otherwise,
it'll keep on coming back.
Again.
And again.
--
Darryl Okahata
darrylo at soco dot agilent dot com
DISCLAIMER: this message is the author's personal opinion and does not
constitute the support, opinion, or policy of Agilent Technologies, or
of the little green men that have been following him all day. |