<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TS Agent Source Port Redirection blocks ODBC connection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-source-port-redirection-blocks-odbc-connection/m-p/68625#M39998</link>
    <description>&lt;P&gt;We have a deployment of the TS Agent on 2008 R2 terminalservers. The TS agent works as designed and reassigns source ports. However, one specific segment of one specific application that is based on MS Access fails to connect to an SQL server when the TS agent service is running.The application's vendor says they don't enforce specific source ports.&lt;/P&gt;
&lt;P&gt;When the segment inside the application is started, in TCPView we see several system tcp sessions on random high ports (60k+) connect to the SQL server. When the agent is active and the call fails, those sessions are using the configured TS agent ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anybody else experienced problems with connecting with ODBC to an SQL server while the TS agent is running?&lt;/P&gt;</description>
    <pubDate>Wed, 25 Nov 2015 13:11:39 GMT</pubDate>
    <dc:creator>CONFORM_Servicedesk</dc:creator>
    <dc:date>2015-11-25T13:11:39Z</dc:date>
    <item>
      <title>TS Agent Source Port Redirection blocks ODBC connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-source-port-redirection-blocks-odbc-connection/m-p/68625#M39998</link>
      <description>&lt;P&gt;We have a deployment of the TS Agent on 2008 R2 terminalservers. The TS agent works as designed and reassigns source ports. However, one specific segment of one specific application that is based on MS Access fails to connect to an SQL server when the TS agent service is running.The application's vendor says they don't enforce specific source ports.&lt;/P&gt;
&lt;P&gt;When the segment inside the application is started, in TCPView we see several system tcp sessions on random high ports (60k+) connect to the SQL server. When the agent is active and the call fails, those sessions are using the configured TS agent ports.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anybody else experienced problems with connecting with ODBC to an SQL server while the TS agent is running?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2015 13:11:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-source-port-redirection-blocks-odbc-connection/m-p/68625#M39998</guid>
      <dc:creator>CONFORM_Servicedesk</dc:creator>
      <dc:date>2015-11-25T13:11:39Z</dc:date>
    </item>
    <item>
      <title>Re: TS Agent Source Port Redirection blocks ODBC connection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-source-port-redirection-blocks-odbc-connection/m-p/68700#M40023</link>
      <description>&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;&lt;SPAN&gt;MS access application opens a large number of TCP connections, probably one for each SQL query. &lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="helvetica" size="2"&gt;&lt;SPAN&gt;These connections are very short lived, but the OS keeps them in TIME_WAIT state for 240 seconds by default. &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;I have seen that these can consume the entire allocated port block.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT face="helvetica" size="2"&gt;&lt;SPAN&gt;By default, TS agent does does not allocate an additional port range.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT face="helvetica" size="2"&gt;&lt;SPAN&gt;This behaviour can be changed with a registry setting HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\TS Agent\Conf\EnableTws &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="helvetica" size="2"&gt;&lt;SPAN&gt;Check out the following DOC : &lt;/SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5345" target="_blank"&gt;https://live.paloaltonetworks.com/docs/DOC-5345&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;FONT face="helvetica" size="2"&gt;&lt;SPAN class="s1"&gt;If EnableTws=0, we will not keep the list of ports in TIME_WAIT status, and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;thus may think that those TIME_WAITed ports are available.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;FONT face="helvetica" size="2"&gt;&lt;SPAN class="s1"&gt;To change this default behaviour, just change EnableTws=1, and new block of&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="s1"&gt;ports will be assigned to the user.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;FONT face="helvetica" size="2"&gt;&lt;SPAN class="s1"&gt;I hope this helps,&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="p1"&gt;&lt;FONT face="helvetica" size="2"&gt;&lt;SPAN class="s1"&gt;-Kim.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2015 10:53:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ts-agent-source-port-redirection-blocks-odbc-connection/m-p/68700#M40023</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2015-11-26T10:53:26Z</dc:date>
    </item>
  </channel>
</rss>

