A server of Network Market Makers RSH application abnormal interrupted exception analysis report

Issue Description
RSH client established a link with RSH(TCP),then server sent ALARM message to client
But,after once RSH established successful 10s,TCP is interrupted,business is down,try several times is the same phenomenon
For RSH application business characteristic,we can solve this problems by close state detecte of firewall
        IP:   Source address =, imep3
IP:   Destination address =,
IP:   No options
TCP:  ----- TCP Header -----
TCP:  Source port = 983
TCP:  Destination port = 514 (RSHELL)
TCP:  Sequence number = 2569436765
TCP:  Acknowledgement number = 3982009346
TCP:  Data offset = 20 bytes
TCP:  Flags = 0x11
TCP:        0... .... = No ECN congestion window reduced
TCP:        .0.. .... = No ECN echo
TCP:        ..0. .... = No urgent pointer
TCP:        ...1 .... = Acknowledgement
TCP:        .... 0... = No push
TCP:        .... .0.. = No reset
TCP:        .... ..0. = No Syn
TCP:        .... ...1 = Fin
TCP:  Window = 49640
TCP:  Checksum = 0x8741
TCP:  Urgent pointer = 0
TCP:  No options
This process is normal mechanism of RSH application,because the aim of this application is client monitor server alarm information,once the server generating a alarm information,then sent to the server at once,but the server have no use for answer this message,so this application is just the server sent messages to cilnet for one direction,after established TCP links,is more safer to close the half links of client to server
After firewall receive FIN message,deal with TCP dialog normally,refurbish aging time of TCP dialog as fin-rst timeout aging time,10s。although configure a long link for ip address of cilnet in firewall,but this configure of long link has no effect   
HRP_M[ZJHZ-PS-WGDCN-FW26-BJ5F/ZC]disp firewall session table  ver source inside
  tcp, (vpn: public -> public)
  zone: trust -> untrust   tag: 86000002
  ttl: 00:00:10  left: 00:00:7  Id: 20411
  <-- packets:0 bytes:0   --> packets:0 bytes:0>

so,after 10s,this TCP SESSION is ageing,business is interrupted
After state-inspection of firewall closedown,firewall can not configure NAT,and can not configure attack defense application too
At the same time,more of session aging time of firewall turn to 30s automatically
So, for some business with few alternation message,need configure long connect