Consider the following scenario:
In this scenario, you may notice that both sides of the TCP connection are closed immediately by the FIN/ACK packet.
- You have internal clients who are trying to access non-web-based application servers in a Microsoft Forefront Threat Management Gateway (TMG) 2010 environment.
- The client traffic passes through an application filter in Forefront TMG that data-flows the traffic in user mode.
- The client or the remote application server half-closes the TCP connection by sending a FIN/ACK packet. In doing this, the client or the remote application server expects the other half of the TCP connection to stay active.
In this scenario, you may notice that both sides of the TCP connection are closed immediately by the FIN/ACK packet.