Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

TCP Half Close for TCP or SOCKS Proxy

TCP Half Close refers to a TCP connection that is half-closed. So if one participant in a TCP connection has initiated FIN in one direction, then it can still receive data from another participant until the second FIN is received from the other direction.

TCP Half Close support is provided for SWG acting as TCP Proxy or SOCKS Proxy, and it is disabled by default. 

TCP Half close is not supported in the following scenarios:

  • SWG configured as a proxy for HTTP/HTTPS content inspection.
  • SWG as SOCKS with a Protocol detection rule enabled.

SOCKS Proxy

  1. Select Configuration > Appliances.
  2. Select the Proxies (HTTP(S), FTP, SOCKS, ICAP ...)
  3. In the configuration pane, scroll down to SOCKS Proxy
  4. Select Enable SOCKS Proxy.
  5. To create a new setting, use one of the following methods:
    • Right-click the configuration pane. Then click Enable TCP Half Close.
    • Click Add right away.
      The ADD SOCKS Proxy Port window opens.
      Click Enable TCP Half Close.
      tcp_half_close_socks.png
  6. Click OK.

TCP Proxy

  1. Select Configuration > Appliances.
  2. Select the Proxies (HTTP(S), FTP, SOCKS, ICAP ...)
  3. In the configuration pane, scroll down to TCP Proxy
  4. Select Enable TCP Proxy.
  5. To create a new setting, use one of the following two methods:
    • Right-click the configuration pane. Then click Enable TCP Half Close.
    • Click Add right away.
      The ADD TCP Proxy Port window opens.
      Click Enable TCP Half Close.
      tco_half_close_tcp.png
  6. Click OK.
  • Was this article helpful?