Description

This article provides information about the half-closed feature and if it is supported on  SRX platforms.

Symptoms

  • TCP, when established, is a bi-directional pipe.

  • A half-closed connection is when the client (or server) sends a FIN and the server (or client) ACKs the FIN, without sending a FIN itself. The timer starts, when this condition is met.

  • Some other devices have the ability to define a half-closed timeout, independent of the TCP timeout.

  • Is this ability also supported on ScreenOS and SRX firewalls?

Solution

ScreenOS and SRX based security devices do not support this feature. When a half-closed condition occurs, the side that has the connection open will use the default TCP timeout that is set on the device.

Modification History

2024-10-25: minor non tech changes

2020-06-26: Article reviewed for accuracy. Article is correct and complete.