Files
geedge-jira/md/OMPUB-972.md
2025-09-14 22:27:11 +00:00

43 lines
1.5 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 【P19现场】现场发现URL封堵有穿透现象
| ID | Creation Date | Assignee | Status |
|----|----------------|----------|--------|
| OMPUB-972 | 2023-07-24T23:04:47.000+0800 | 杨威 | 已解决 |
---
在现场发现url封堵有穿透现象通过wireshark抓包发现
1.chrome 发起http请求时同时创建2个会话。
2.封堵对第一个会话有效,对第二个会话失效。
3.第二个会话在三次握手后会很长一段时间没有数据传输45s以上此时第一个会话被阻断第二个会话直接从url请求开始此时出现穿透
图片中tcp.stream eq 22 为第二个会话, tcp.stream eq 21为第一个会话
https://stackoverflow.com/questions/47336535/why-does-chrome-open-a-connection-but-not-send-anything
**yangwei** commented on *2023-07-31T00:55:02.575+0800*:
问题原因为功能端新增opening timeout参数默认10s测试时的会话从syn到第一个data包间隔45s在opening状态触发超时导致无法正确阻断
自[TSG-16300] OS支持配置TCP的opening timeout和closing timeout参数 - Geedge Networks Jira后提供opening参数且功能端同步将opening timeout参数提升至60s
---
# Attachments
Attachment: chuantou_1.pcap
[chuantou_1.pcap](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/41767/chuantou_1.pcap)
Attachment: screenshot-1.png
![screenshot-1.png](https://gfwleak.exec.li/admin/geedge-jira/raw/branch/master/attachment/41768/screenshot-1.png)