Solved

TMG Server Fills Up and Holds TCP Ports in TIME_WAIT Status Until Ports Are Exhausted

Posted on 2010-11-22
1
1,282 Views
Last Modified: 2013-11-16
We have a two node TMG implementation running SP1. The first node (10.0.1.9) runs like a champ. Node two (10.0.1.10) runs OK but then performance nose-dives eventually leading to a completely non-functional server. We have found through netstat that thousands and thousands of ports on node two are tied up in a TIME_WAIT to the cluster IP address (10.0.1.8) and eventually there are no ports available to serve new connections. We have tried increasing the ports and decreasing the timeout but neither seems to be working. Any ideas? Any questions I can answer to move this along?
0
Comment
Question by:PHFrench
1 Comment
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 500 total points
ID: 34319412
Run the best practice analyser for tmg againsty both nodes - compare the outputs.
Are both nodes running sp1 and the sp1 update for tmg?
Are you using ftmg with NLB or did you set up NLB then install FTMG? Are you operating with isp load-balancing/failover?

Which addresses are being kept in wait-state - the external NLB or the internal NLB?

What are the default gateway settings for internal systems - a specific ftmg node or the vip address?
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
The Need In an Active Directory enviroment, the PDC emulator provide time synchronization for the domain. This is important since Active Directory uses Kerberos for authentication.  By default, if the time difference between systems is off by more …
This Micro Tutorial demonstrates using Microsoft Excel pivot tables, how to reverse engineer competitors' marketing strategies through backlinks.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question