GFI Software

Welcome to the GFI Software community forum! For support please open a ticket from https://support.gfi.com.

Home » GFI User Forums » Kerio Control » 3-way handshake not completed (Cannot connect mail server through Kerio Control)
3-way handshake not completed [message #118874] Mon, 26 January 2015 21:18 Go to next message
Gaby is currently offline  Gaby
Messages: 34
Registered: March 2010
I have Kerio Control firewall with two WAN connections with load balancing. One of it points to an internal mail server (Kerio Connect).

There's a weird behavior here. If you want to access webmail from certain external addresses there is no response (cannot connect). If from the same problematic address you access through the other WAN connection there is no problem.

But, oddly from other addresses there is no problem.

Looking in the debug report I found this error from one problematic address:


[21/Jan/2015 21:53:17] {pktdrop} packet dropped: 3-way handshake not completed (from Internet Telmex, proto:TCP, len:41, 190.97.45.65:65388 -> 200.80.203.43:80, flags:[ ACK ], seq:2586090912 ack:20916154, win:252, tcplen:1)

I believe this is the reason but I'm not completely sure.

Any help will be appreciated.

Thanks in advance.
Re: 3-way handshake not completed [message #118899 is a reply to message #118874] Wed, 28 January 2015 04:28 Go to previous messageGo to next message
mlee (Kerio)
Messages: 211
Registered: October 2012
Location: Sydney
To confirm, you can disable the 3-way handshake requirement (Edit /var/winroute/winroute.cfg, change the value of the variable Require3WayHandshake from 1 to 0, reboot Kerio Control)

M.


PTSD. BP. OCD. ASPD. BPD. Certified.
Re: 3-way handshake not completed [message #127450 is a reply to message #118874] Wed, 27 January 2016 23:56 Go to previous message
dllcoder is currently offline  dllcoder
Messages: 97
Registered: November 2010
Location: RUS,MSK
Hello,

I have the same weird behavior with access to internal web-server from external addresses in same conditions - 2 WAN with load balancing.


Kerio Control, Connect, Workspace[R.I.P.] (~250 users each) Admin/User
Previous Topic: IPV6 DUID for fixt ip range
Next Topic: KERIO Control SIP one way audio
Goto Forum:
  


Current Time: Wed Jun 07 03:36:31 CEST 2023

Total time taken to generate the page: 0.02342 seconds