Fixing Sonicwall TCP timeouts

Sonicwall devices appear to ship with very aggressive TCP timeout settings – these can affect long-lived TCP transfers such as backups for CyberSecure.

To increase the TCP timeout setting:

  1. Login to your Sonicwall device
  2. Go to the top-level menu item “Firewall”
  3. Choose “TCP Settings”
  4. Change the “Default TCP Connection Timeout” from its default value of 15 minutes to 720 minutes (that’s 12 hours)
  5. You may need to restart the device for the changes to take effect

Further troubleshooting

If the above process does not resolve the issue, then a per-rule timeout change may be required.

  1. Create a new Firewall access rule
  2. Allow outgoing SFTP port 22 to 203.209.195.103
  3. Under the “Advanced” tab change the TCP timeout to something longer than the default 15 minutes (perhaps 720 minutes, 12 hours)