Forum Discussion

hpanaman_163642's avatar
hpanaman_163642
Icon for Nimbostratus rankNimbostratus
Jul 14, 2014

Putty Timeout when AFM VPN is used

Hi All,

 

I am using the F5 AFM VPN to connect to the production network. Upon successful connection, I use putty client to connect to the production servers. Few minutes of inactivity (around 1-2 mins) makes the putty session to timeout. The "time-out” value on /etc/profile of the linux server (to terminate the inactive terminals) is set to 900 seconds (15mins), but the putty session timesout earlier (arnd 1-2 mins).

 

Is there any parameter that needs to be changed on the AFM?

 

Thanks

 

Cheers, hpanaman

 

3 Replies

  • Hi,

     

    Did you mean Access Policy Manager (APM) VPN SSL Network Access?

     

    Advanced Firewall Manager (AFM) is the Network Firewall module with dos protection of BIG-IP suite.

     

    If you have administrator access to the server, please check the ClientAliveInterval, TCPKeepAlive and ClientAliveCountMax options in the SSHd configuration file.

     

    Also, try enable TCP Keepalives in Putty Connection options.

     

    Finally, use tcpdump in the BIG-IP system to capture a whole Putty connection and paste the output here to see the details.

     

    Bye.

     

  • Hi,

     

    Following is the settings in my server: /etc/ssh/ssh_config file Host * GSSAPIAuthentication yes ServerAliveInterval 900 ServerAliveCountMax 3

     

    /etc/ssh/sshd_config

     

    PrintLastLog yes

    TCPKeepAlive yes

     

    UseLogin no UsePrivilegeSeparation yes PermitUserEnvironment no Compression delayed

    ClientAliveInterval 900 ClientAliveCountMax 3

     

    ShowPatchLevel no UseDNS yes PidFile /var/run/sshd.pid MaxStartups 10

    Also enabled the TCP Keep alives in putty. Also enabled the keepalives--> sessions--> Connections-->sessions between keepalives set to 900.

     

    All the above configuration on the server and the putty client doesnt help. I still get putty client timed out in 1-2 mins. Can help?

     

    Cheers, hpanaman

     

  • Hi,

     

    Following is the settings in my server: /etc/ssh/ssh_config file Host * GSSAPIAuthentication yes ServerAliveInterval 900 ServerAliveCountMax 3

     

    /etc/ssh/sshd_config

     

    PrintLastLog yes

    TCPKeepAlive yes

     

    UseLogin no UsePrivilegeSeparation yes PermitUserEnvironment no Compression delayed

    ClientAliveInterval 900 ClientAliveCountMax 3

     

    ShowPatchLevel no UseDNS yes PidFile /var/run/sshd.pid MaxStartups 10

    Also enabled the TCP Keep alives in putty. Also enabled the keepalives--> sessions--> Connections-->sessions between keepalives set to 900.

     

    All the above configuration on the server and the putty client doesnt help. I still get putty client timed out in 1-2 mins. Can help?

     

    Cheers, hpanaman