Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
24.1 Legacy Series
»
Connection time-out 900s - State violatie rule
« previous
next »
Print
Pages: [
1
]
Author
Topic: Connection time-out 900s - State violatie rule (Read 566 times)
Mwason
Newbie
Posts: 2
Karma: 0
Connection time-out 900s - State violatie rule
«
on:
April 12, 2024, 01:56:46 pm »
Hello,
I have a setup with multiple VLAN's.
They all can connect to the 'main'vlan by a floating rule.
Connections can be made but after 900s (since Firewall mode conservative active, in normal-mode much earlier!) the connections time-out and are blocked by 'Default deny/state violation rule'.
But are rebuild directly after accepted by the 'floating rule'.
(see attachment)
How can I prevent the connection to time-out and/or being blocked.
Looking forward at your suggestions...
Mwason
Logged
Patrick M. Hausen
Hero Member
Posts: 6744
Karma: 568
Re: Connection time-out 900s - State violatie rule
«
Reply #1 on:
April 12, 2024, 02:05:11 pm »
What type of connections? Can you enable some sort of keepalive? E.g. in SSH?
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
Mwason
Newbie
Posts: 2
Karma: 0
Re: Connection time-out 900s - State violatie rule
«
Reply #2 on:
April 12, 2024, 03:51:36 pm »
Via TCP they connect to a adress at port 30300.
There is only temporarely traffic but the connection should stay open...
Logged
Patrick M. Hausen
Hero Member
Posts: 6744
Karma: 568
Re: Connection time-out 900s - State violatie rule
«
Reply #3 on:
April 12, 2024, 04:28:27 pm »
OPNsense will timeout any connection if there is no packet flow. Either implement keepalive on the application side or disable state tracking for these rules. IIRC that means you need a reverse rule for the packets to flow in both directions. Never needed this so far.
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
24.1 Legacy Series
»
Connection time-out 900s - State violatie rule