Solved

Sonicwall TZ215 max connections

Posted on 2014-01-14
7
1,323 Views
Last Modified: 2014-01-18
First, I’m not a firewall expert. For the past couple days, our Sonicwall TZ215 will start to fill up and max out the connections causing lots of problems. No internet access, unable to connect to other network devices, etc. The max is 24000.
It’s like the device is under attack. The logs don’t seem to show anything. It could be something from the inside for all I know. Where’s the best place on the firewall to look to resolve this? I have to end up bouncing it to clear the connections.
0
Comment
Question by:CTmountainbiker
  • 3
  • 2
  • 2
7 Comments
 
LVL 11

Expert Comment

by:Miftaul
ID: 39779697
Please go system, status page.
It will show number of active sessions, max session opened, and maximum supported.Sonicwall
0
 

Author Comment

by:CTmountainbiker
ID: 39779741
See attached
CaptureSW.JPG
0
 
LVL 11

Expert Comment

by:Miftaul
ID: 39779809
In 54min the device is up, its too many tcp connections.

Are you doing content filtering, if not, please enable and stop unproductive traffic. You might need to upgrade to higher end device.

Have you checked the hosts for virus/malwares.

Can you update the firmware to 5.9.
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 

Author Comment

by:CTmountainbiker
ID: 39780110
We do have content filtering enabled. Also, every workstation is running an up-to-date version of anti virus. How do you quantify the connections? Is there a way to determine what constitutes them?
0
 
LVL 24

Accepted Solution

by:
diverseit earned 500 total points
ID: 39782485
Hi CTmountainbiker,

Yes, you can see all the connections running currently in the Connection Monitor (System > Diagnostics > Diagnostic Tool: Connection Monitor).

Let me know if you have any other questions!
0
 

Author Comment

by:CTmountainbiker
ID: 39782713
Very good! thank you
0
 
LVL 24

Expert Comment

by:diverseit
ID: 39790583
Glad I could help and thanks for the points!
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now