On Jun 7, 2012, at 10:29 AM, Michael Sierchio wrote:
> On Thu, Jun 7, 2012 at 10:27 AM, Michael Sierchio <[email protected]> wrote:
>> net.inet.tcp.finwait2_timeout: 60000  <- ms, ten minutes
> 
> I can't do arithmetic, but you get the idea. A full minute.

Yes; that's already shorter than possible MAXTTL value of packets, which can be 
anywhere up to 255 seconds (~= 5 minutes).

Well, it's usually OK for a webserver to decide that it doesn't need to wait 
around for clients to properly shutdown their HTTP connections, but one might 
want to be more careful about zapping sockets early for HTTPS/SSL connections 
(ie, an online store doing a CC transaction or the like).

Regards,
-- 
-Chuck

_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[email protected]"

Reply via email to