JuniperForum.com
September 07, 2010, 07:34:12 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: If you have an interesting idea for an article or knowledgebase entry, please submit it!
 
  Home Help Login Register  
* *
Pages: [1]
  Print  
Author Topic: Session Utilization Full  (Read 4126 times)
biosphere
Newbie
*
Posts: 3


View Profile
« on: December 12, 2006, 09:19:08 PM »

Hi All,

Not sure whether you all have encounter this; lately i've been encounter our screenOS V5.3 have the issues of reaching the session utilization full very fast. just want seek confirmation on this from all of you, whether this is the screenOS problem or other problem. Has anybody enocuntered the same issue as mine ?, just would like to seek advice from all of you, any suggestion for this issue, thanks in advance.
Logged
signal15
Administrator
Sr. Member
*****
Posts: 480


View Profile WWW
« Reply #1 on: December 12, 2006, 11:26:19 PM »

Did you put in any custom services and set the session timeout to never?

I had a client make an "any" service with no timeout and permitted traffic to a host.  Someone portscanned the host, and it immediately used up all the sessions.  Check your services.
Logged
biosphere
Newbie
*
Posts: 3


View Profile
« Reply #2 on: December 13, 2006, 12:37:01 AM »

Hi Signal15,

Thanks for your reply and advice. Just would like to seek your advice on this; for us currently we so have few custom services created, but it's not in use and we've set all timeout value to 30. btw, for your info, we do have and e-mail system running on MS exchange and AD, and we have a rule with particular high traffics which is the rule created for this exchange and AD traffics. (out of 4000+ session available, and AD and exchange traffics is using 2400+ and is increasing, and abt the AD port that's using, they are using RPC and the port range for that service is very large)

Do you think this is a MS exchange and AD connection bugs that caused this?, and just to seek your advice and suggestion, is there any solution we can try out to resolve this issue?

Your advice is very much apprecited, Thanks a lot in advance.
Logged
signal15
Administrator
Sr. Member
*****
Posts: 480


View Profile WWW
« Reply #3 on: December 13, 2006, 01:49:07 PM »

Can you run your session data through http://tools.juniper.net/fsa/

The timeout value is 30 on the exchange service object?  Can you double check that?  How many clients are accessing exchange at any given time?  Has it always been like this or did it just start doing it?
Logged
joekim13
Newbie
*
Posts: 37


View Profile
« Reply #4 on: January 10, 2008, 10:48:17 PM »

it could be that those are legitimate session count and you just need a higher end box 
Logged
Pages: [1]
  Print  
 
Jump to:  

Navigation

Donate

Please consider donating if we've saved you time or money. It helps pay for the bandwidth, equipment, and hosting charges to keep this site running

Tools

Submit Article/KB - Do not submit questions here.

Recent

Stats

Members
  • Total Members: 22514
  • Latest: Deepy
Stats
  • Total Posts: 40575
  • Total Topics: 11249
  • Online Today: 77
  • Online Ever: 393
  • (August 06, 2008, 07:40:57 AM)
Users Online
Users: 3
Guests: 62
Total: 65
TinyPortal v1.0 beta 4 © Bloc
Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!

Sponsored in part by CollarWise

Page created in 0.231 seconds with 38 queries.