#1 Global Leader in Data Resilience

Troubleshooting Signature-Based Firewalls

KB ID: 2140
Product: Veeam Backup & Replication | 9.5 | 10 | 11 | 12 | 12.1 | 12.2 | 12.3 | 12.3.1
Veeam Backup for Microsoft 365 | 6.0 | 7.0 | 7a | 8 | 8.1
Veeam Backup for Microsoft Office 365 | 2.0 | 3.0 | 4.0 | 5.0
Veeam Agent for Microsoft Windows | 2.1 | 2.2 | 3.0.2 | 4.0 | 5.0 | 6.0 | 6.1 | 6.2 | 6.3 | 6.3.1
Veeam Cloud Connect | 9.5 | 10 | 11 | 12 | 12.2 | 12.3
Published: 2016-07-12
Last Modified: 2025-04-28
Languages: JP
mailbox
Get weekly article updates
By subscribing, you are agreeing to have your personal information managed in accordance with the terms of Veeam's Privacy Notice.

Cheers for trusting us with the spot in your mailbox!

Now you’re less likely to miss what’s been brewing in our knowledge base with this weekly digest

error icon

Oops! Something went wrong.

Please, try again later.

Challenge

Summary

Data transfer is failing across a connection that is protected by an advanced firewall. The firewall uses signature-based detection. Relevant features may have names like antivirus, anti-spyware, intrusion prevention, or application control.

Reported Firewalls

This may affect any make or model of a firewall with similar features, but support cases have been opened for:

  • Check Point
  • Cisco
  • SonicWALL
  • Fortinet appliances
  • Palo Alto
  • Sophos
  • CrowdStrike
  • Kaspersky
     

Impact Examples

Any type of data transfer may be affected. This problem may manifest in a wide variety of error messages and failure patterns. It may appear random or consistent.

Veeam Backup & Replication or Veeam Cloud Connect

For the Veeam Backup & Replication product, this can affect all job types. A common failure pattern is for the transfer of specific VM's disks to fail at or around the same percentage of completion repeatedly.

Common error messages include:

  • A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond
    
  • An existing connection was forcibly closed by the remote host.
    
  • Unstable connection: unable to transmit data.
    

Depending on the job type and the version of Veeam Backup & Replication, connection failures may cause the job to fail immediately, or the connection may be retried several times. While the connection is retried, the job may appear to be frozen because it is unable to transmit data. For more information, see:
Resume on Disconnect
Backup Copy: Automatic Job Retries
WAN Acceleration: Data Transport on WAN Disconnect

Veeam Backup for Microsoft 365 

With Veeam Backup for Microsoft 365 this issue may appear with an error message:

A blocking operation was interrupted by a call to WSACancelBlockingCall

Cause

Data transferred by Veeam software products can contain a potentially unlimited variety of data blocks. Because the traffic is compressed (and in most cases encrypted), data blocks analyzed by a firewall will be different from data as it exists in production. Over the long term, this approximates feeding random data into the signature-based threat detector: false positives are inevitable.

Data transfer is not actually random: a particular data block will always have the same signature after compression and encryption. If the source data does not change, the same blocks will be resent on every reconnect attempt and every retry of the job. In this case, the firewall will close the network connection every time a Veeam product attempts to transfer that data block because the firewall incorrectly detects a pattern of data within that block that matches the signature of a known threat.

Solution

It is advisable to begin by reviewing any logging available from the firewall to identify interactions and false detections that interfere with Veeam software data transmissions. Then, create exclusions for Veeam data traffic.

  • In most cases, for Veeam Backup & Replication, Veeam Agent for Microsoft Windows, and Veeam Agent for Linux, the relevant traffic will be between servers when data is transferred over the transport ports of 2500-3300 (TCP). This range can be configured for each managed server in the backup infrastructure settings.
  • Cloud Connect Service Providers should create exclusions for data traffic sent to Cloud Gateways on port 6180 (TCP and UDP).
  • For Veeam Backup for Microsoft 365, data transferred over port 443 (TCP) can be affected by this issue.
  • For more information on port ranges, find the relevant product or component user guide in the Help Center and consult the Used Ports page.
  • For information on configuring exclusions on a specific firewall appliance, please contact the firewall vendor.

More Information

To isolate the firewall, temporarily disable all signature-based features in the firewall’s configuration. For best results, do this while data transfer appears frozen – traffic should resume in no more than a few minutes. In some cases, the firewall may allow you to disable specific sites or zones selectively; this can be useful as a solution, but it is not a good isolation step because such features are easily misconfigured.

Reset packets generated by firewall appliances can usually be distinguished from normal traffic by their IP time to live. For example, if most packets in a TCP stream have a TTL of 128, the reset packet that closes the stream has a TTL of 64, the connection was closed by a firewall.

Firewall features that block encrypted key exchange will block most WAN connections used by Veeam Backup & Replication.
To submit feedback regarding this article, please click this link: Send Article Feedback
To report a typo on this page, highlight the typo with your mouse and press CTRL + Enter.

Spelling error in text

Thank you!

Thank you!

Your feedback has been received and will be reviewed.

Oops! Something went wrong.

Please, try again later.

You have selected too large block!

Please try select less.

KB Feedback/Suggestion

This form is only for KB Feedback/Suggestions, if you need help with the software open a support case

Veeam Backup & Replication
Veeam Data Cloud for Microsoft 365
Veeam Data Cloud for Microsoft Entra ID
Veeam Data Cloud for Salesforce
Veeam Data Cloud for Microsoft Azure
Veeam Data Cloud Vault
Veeam Backup for Microsoft 365
Veeam Backup for Microsoft Entra ID
Veeam Backup for Salesforce
Veeam ONE
Veeam Service Provider Console
Veeam Agent for Microsoft Windows
Veeam Agent for Linux
Veeam Backup for Nutanix AHV
Veeam Backup for AWS
Veeam Backup for Microsoft Azure
Veeam Backup for Google Cloud
Veeam Backup for Oracle Linux Virtualization Manager and Red Hat Virtualization
Veeam Management Pack for Microsoft System Center
Veeam Recovery Orchestrator
Veeam Agent for Mac
Veeam Agent for IBM AIX
Veeam Agent for Oracle Solaris
Veeam Cloud Connect
Veeam Kasten for Kubernetes
By submitting, you are agreeing to have your personal information managed in accordance with the terms of Veeam's Privacy Notice.
Verify your email to continue your product download
We've sent a verification code to:
  • Incorrect verification code. Please try again.
An email with a verification code was just sent to
Didn't receive the code? Click to resend in sec
Didn't receive the code? Click to resend
Thank you!

Thank you!

Your feedback has been received and will be reviewed.

error icon

Oops! Something went wrong.

Please, try again later.