Which PuTTY keep-alive interval prevents NAT timeouts without triggering server-side security alerts?
0 reputation · 03 Jun 2020, 02:25 UTC
0 reputation · 03 Jun 2020, 02:25 UTC
PuTTY provides a mechanism under Connection > SSH to send null packets at specific intervals to maintain active sessions. This is primarily used to prevent firewalls or NAT gateways from dropping idle TCP connections.
While this client-driven behavior ensures session persistence, there is a tension between maintaining the connection and avoiding security triggers. Setting the interval too low may cause security appliances to flag the traffic as a denial-of-service attempt, while setting it too high may fail to prevent the timeout.
Does the interaction between PuTTY's keep-alive packets and the server's ClientAliveInterval create redundant traffic that impacts performance? What is the recommended interval to balance stability against security appliance sensitivity?
For most consumer‑grade NAT devices the idle‑timeout is 30–45 seconds. Setting PuTTY’s Connection > Seconds between keepalives to 60 seconds keeps the TCP session alive while staying well below the thresholds that most server‑side intrusion‑detection systems flag.
ClientAliveInterval is a separate SSH‑level keep‑alive sent from server to client.60.30 for the keep‑alive.sshd logs for any idle timeout or keep‑alive entries that coincide with the interval you set.What is the exact idle‑timeout value configured on your NAT gateway? Knowing that number lets us fine‑tune the keep‑alive precisely.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.