Cisco Firewall :: ASA 60 Minute Inactivity Timeout?

Feb 15, 2013

We had an issue the other day where doing backups through the firewall (don't ask) caused the "control" session to timeout while the backups were still going on over the "data" connection.  This broke the backup about two hours into the job.  My first thought was that the backup solution vendor should implement some kind of tcp keepalive for the control connection.  A packet capture showed they indeed were --  after 2 hours!  Ah ha!  Busted!  How could they choose such a poor choice of TCP keepalive timer for their application that would not be compatible with the 60 minute inactivity timer that so many firewall vendors use (Cisco, Juniper, Checkpoint and Fortinet all use a default 60 minute inactivity timer for TCP)?
 
Well, a colleague of mine pointed out that there is actually an old RFC that covers this.  RFC 1122.  It says:
 
Keep-alive packets MUST only be sent  when no data or acknowledgement packets have been received for the  connection within an interval.  This interval MUST be configurable and  MUST default to no less than two hours.
 
Now I know that RFC is old (October 1989), but that's all I could find.  Is there something that supercedes that?  Maybe common sense perhaps?  I understand not wanting to fill up your connection table because of mis-behaving applications, but I'm just looking for ammunition to use against the backup solution vendor.  Surely they're going to point to this RFC.

ASA(config)# timeout conn ?
 
configure mode commands/options:

  0:0:0 | <0:5:0> - <1193:0:0>  Idle time after which a TCP connection state
will be closed, default is 1:00:00
  <0-0>  Specify this value to never time out

View 1 Replies


ADVERTISEMENT

Cisco Firewall :: ASA 8.2(5) - Uauth Absolute Timeout Disabled And Inactivity Timeout Set To 48 Hour

Nov 26, 2012

ASA 8.2(5), uauth absolute timeout is disabled and inactivity timeout is set to 48 hours:
 
timeout xlate 48:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:00:00 absolute uauth 48:00:00 inactivity
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
 
Users still get kicked out every 8 hours and they have to reauth. This is a logging message:
 
%ASA-5-109012: Authen Session End: user 'john', sid 839, elapsed 28801 seconds

View 1 Replies View Related

Cisco Application :: A3 (1.0) Default HTTPS Inactivity Connection Timeout

Mar 28, 2012

default inactivity connection time out for A3(1.0) So by defult any tcp connection(http or https) will be timed out in an hour. [code]Was this change in the A4(2.0) code or is it still the same? I heard a TAC engg say that default inactivity timeout for http and https are now 5 mins that is 300 seconds.

View 3 Replies View Related

Cisco Routers :: RV082 Timeout After Every 30 Minute?

Nov 14, 2012

i purchases cisco rv 082. i set MTU vale at 1500.i use public IP for WAN and just using one WAN.

View 4 Replies View Related

Cisco Firewall :: ASA 8.4(3) Timeout Configuration

Oct 3, 2012

I would like to know something with more accuration about idle timeout configuration. In particular why is impossible to set "half-closed connections"  to a value lower than 5 minutes neither through a policy-map? In my  particular scenario, my asa is used to nat mobile phones traffic, it  should be advisable to use less than 5 minutes
 
In my configuration I've set the timers as follows:
 
.
timeout xlate 0:15:00
timeout pat-xlate 0:00:30
timeout conn 0:14:00 half-closed 0:05:00 udp 0:02:00 icmp 0:00:02

[Code].....

View 4 Replies View Related

Cisco Firewall :: ASA 8.4.1 SSH Timeout Vulnerability?

Feb 20, 2013

Faced this recent vulnerability?

[URL]
 
My understanding is that for ASA 8.4.1 and prior, there's a vulnerability that opening many ssh sessions and one of them times out, the firewalls crashes! 
 
As we have many customers with ASA using 8.2.5(26) (for example) I'd like a confirmation that for fixing that bug I need to upgrade my ASA image to at least 8.4.x.Case that, I believe that all the former firewall configuration must be reviewed because 8.2.x version has many different commands that 8.4.x (for example, NAT)

View 19 Replies View Related

Cisco Firewall :: 5510 ASA Connection Timeout For DNS

Jan 31, 2012

I recently had a firewall that wasn't passing traffic (ASA 5510 running software version 9.1).It turned out it had 130000 active connections.  Doing a "clear conn port 53" dropped the active connection count back to 38k, and the firewall started passing traffic again.

View 7 Replies View Related

Cisco Firewall :: ASA 5520 RDP Session Timeout?

Jun 4, 2012

I have inherited the support of an ASA5520 running 8.0(3)12 code and I believe I have a pretty simple question here that I haven't been able to figure out on my own. I have a few users that connect to the box via IPSEC VPN client connections. They want to be able to leave up a RDP based connection, for monitoring purposes, for a most of the day, but thier RDP connection keeps getting discounnted after a few hours. The VPN connection never gets disconnected, just the RDP session running through it.  I have another box running 8.0(4) code and they can leave up the RDP sessions as long as they like without getting disconnected from the server(s). I have compared the configs of both boxes and don't see any glsring differences in regards to the configuration that would cuase the RDP sessions to either to stay up or be disconnected after an inactivity type scenario.
 
What to look for in regards to identifying the timer that is disconnecting the RDP session after a period of time.

View 2 Replies View Related

Cisco Firewall :: Static NAT SYN Timeout - ASA 5505

Aug 30, 2011

I have a 5505 for a small business that has one web server.  The web server has a static NAT entry to an IP address and not an interface.  There is an access rule allowing any HTTP traffic to the outside IP of the web server.  From the web server I can't access the Internet.
 
All other computers on the network can access the Internet using a dynamic nat rule that uses the outside interface. The web server is accessible from a computer behind the firewall.
 
If I delete the static NAT entry for the web server I can get on the Internet.
 
I have turned debugging on and see that an outbound connection is built and then 30 seconds later the connection is torn down with the bytes 0 SYN Timeout message.
 
I am running 8.0(5).

View 3 Replies View Related

Cisco Firewall :: Connection Timeout ASA 5520?

Oct 25, 2011

I configured multiple vlan on my Cisco ASA5520. Everything work perfectly except RDP (3389) connections. The connections are established but but after a period of inactivity, the user is disconnected from server (black screen). The same problem happens with other type of connections (client/server), exemple : Oracle, file sharing. Before installing the ASA, computers and servers were in the same vlan and it worked well.
 
There's a notion of inter vlan timeout connection ?

View 5 Replies View Related

Cisco Firewall :: ASA5505 What Does A Pinhole Timeout Indicate

Aug 18, 2011

What does a pinhole timeout indicate? [code]
 
ASA 5505 8.4(2)

View 2 Replies View Related

Cisco Firewall :: Tcp Flags And Timeout On ASA55XX 8.4(3)

Oct 18, 2012

I would like to understand someting about the behaviour of ASA with our traffic scenario and the management of  tcp sessions.
 
1) In particular we noticed that we have connections with the flags Fin without any acknowledgement. The session is silent (the bytes counters aren't incremented) but it remains in the session table as an established connection with the idle timeout of an established conn.
 
We have about 20%  (60K on 300K total) of conns in this state: at our eyes it seems to be an incorrect behaviour...
 
TCP OUTSIDE 62.149.128.151:110 INSIDE 10.254.158.12:61527, idle 0:11:36, bytes 433, flags UFIO
TCP OUTSIDE 17.151.0.200:443 INSIDE 10.254.229.94:52367, idle 0:01:25, bytes 4597, flags UfIO
TCP OUTSIDE 184.169.79.33:443 INSIDE 10.255.249.146:60143, idle 0:10:39, bytes 5590, flags UFIO
TCP OUTSIDE 157.55.235.158:80 INSIDE 10.170.37.102:62421, idle 0:00:53, bytes 1770, flags UfIO
 
2) On the connections considered as half -closed we have received an ack to the fin (r or R flag is present), we would like to set the idle timeout to a value lower than 5 minutes but we were not able to reach that result
 
timeout pat-xlate 0:00:30
timeout conn 0:10:00 half-closed 0:05:00 udp 0:02:00 icmp 0:00:02
!
access-list timeoutClass extended permit tcp any any eq www
access-list timeoutClass extended permit tcp any any eq 8080
class-map timeoutClass
match access-list timeoutClass
class timeoutClass
 
3) And this type of conns with a Fin on both side that I'm not able to understand... with an ack on one of the side how can I have the other fin??
 
TCP OUTSIDE 69.171.247.38:443 INSIDE 10.168.139.244:51236, idle 0:11:28, bytes 10536, flags UfFIO
TCP OUTSIDE 69.171.247.38:443 INSIDE 10.168.139.244:51234, idle 0:12:22, bytes 9070, flags UfFIO
TCP OUTSIDE 88.40.119.73:36962 INSIDE 10.255.93.162:36875, idle 0:13:27, bytes 3562, flags UfFIO

View 3 Replies View Related

Cisco Firewall :: Telnet Timeout While VPN Connected Via ASA 5520?

Jun 2, 2010

When users are VPN connected their telnet sessions timeout after an hour of inactivity. Looking at the connections on the firewall they are showing as idle. Is there a configuration change or something else that has to be modified?

View 2 Replies View Related

Cisco Firewall :: Initial Connections To SQL Servers Timeout Through ASA 8.2(1)

Aug 23, 2012

I am on version 8.2(1) of ASA Code.When accessing a SQL server on a secure internal interface,(Traffic is sourcing from DMZ) i'm getting some timeouts on the initial connection on port 1433.   All subsequent connections work fine.   Packet tracer shows the connection builds properly, and shouldn't have a connectivity issue.   The problem server is a webserver that connects back through the firewall to access the SQL server on port 1433.    We also have many other webservers in the DMZ which access the same SQL server, but do not have the same timeout issues.   Here are my timeouts, from the config
 
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
arp timeout 14400
 
 I've seen a couple articles about increasing the tcp timeout to 3 hours for the DMZ interface?

View 1 Replies View Related

Cisco Firewall :: Verify Idle-timeout On ASA 5510?

Apr 13, 2011

How to verify on the asa 5510 , the vpn-idle timeout,is running on default setting(30mts)

View 3 Replies View Related

Cisco Firewall :: Asa5510 Idle TCP Connection Timeout With Flags

May 14, 2012

I have ASA 5510 with 8.2.4 and 8.0.x OS and all seem to have common problem of idle TCP connections not timing out. The host to host connections are coming over VPN tunnels. I have default timeouts on all the firewalls. I have tried changing global timeouts and as well as host specific timeouts using MPF but doesn't work at all ! The problem is when TCP connections are sitting idle in conn table for days and when connection limit of 50,000 conns reach the firewall starts behaving unpredictably dropping packets or unresponsive! I need the unused idle connections to timeout which is NOT happening either by changing global values or MPF.

View 1 Replies View Related

Cisco Firewall :: PIX515 - Timeout ICMP / Access Lists?

Mar 29, 2011

I am using a Pix 515 with IOS 8.0(3).I have in my access list on the outside interface.......access-list outside_access_in extended permit icmp any 12.23.34.0 255.255.255.0 echo access-list outside_access_in extended permit icmp any 12.23.34.0 255.255.255.0 echo-reply.......in order to allow ping requests and ping replies into my inside network. This certainly works since I can ping the inside from outside and vice versa, but in the ASDM display of access rules, the hit count for these two lines is always zero. If I run 'show access-list', the hit count for these lines is non-zero.
 
Why doesn't the hit count show up in the ASDM gui display?Also, I have read that the PIX does not treat ICMP in the same way as TCP or UDP and there is no stateful behaviour towards ICMP.  However, if I set up a continuous ping from outside to inside and then disable the above access list rule allowing echo requests towards the inside, the ping continues whereas I would expect it to stop.
 
In the config there is 'timeout icmp 00:00:02' if there is no stateful connection for ICMP, why is there a timeout value for it?

View 4 Replies View Related

Cisco VPN :: ASA 5510 / VPN Tunnel Drops Due To Inactivity?

Dec 12, 2011

I am using a Cisco ASA 5510. Our tunnels always drop due to inactivity, which is a security issue I understand, and it only takes some "interesting traffic" to bring it back up. My problem is that it looks like the interesting traffic has to originate from my side of the tunnel, when our clients send traffic and the tunnel is down due to inactivity it does not come back up. Is there a setting that I am overlooking that will make it come back up no matter who sends traffic? Or, is there a way to make it stay up through inactivity?

View 4 Replies View Related

Cisco VPN :: RV042 Tunnel Inactivity Disconnect

Oct 16, 2011

I have VPN Gateway to Gateway VPN tunnels set from my central office to four remote sites. The tunnels have always been problematic. Started out with five Linksys RV042 v2 devices these had problems with handshake, sometimes would disconnect during this process and had to click disconnect button on either device and this wouold force the tunnel to rebuild. Recently upgrade central device to a Cisco RV042 v3 device. Good news is that this seems to have corrected the handshake issue but now each of the remote sites are having problems during periods of inactivity losing tunnel. The staff at the remote site indicate that they have to close out application and restart router to rebuild the tunnel.

All tunnels are Gateway to Gateway static IP addresses. They all will connect and behave as expected until they reach a certian period of inactivity. I have searched all over Cisco, Linksys, and Google have seen problems similar but no consistant or logical solutions so I thought since I am slowly upgrading my network from my initial equipment which was truely purchased based on cost alone to adding more Cisco equipment. However since this is among the first of my upgrade moves and the improved equipment is creating more problems than my older less expensive equipment I needed a solution to the problem before submitting additional PO's to upgrade switches and firewall products.

View 2 Replies View Related

AR9285 - Wireless Disconnects Upon Inactivity?

Jun 4, 2011

how to tweak my laptop so that the wireless access does not get disabled after a short period (approx 15 min) of inactivity. It's really annoying to have to reconnect every time this happens.

Using an Atheros AR9285 wireless card in an Asustek N61Jv laptop.

View 2 Replies View Related

Cisco Firewall :: ASA5505 - SSH Timeout / Unable To Access Device From Host

Jul 19, 2007

I have an ASA5505 running ver 8.0(2). I have configured the ssh timeout, ssh host commands and did the crypt o key gen. I am unable to access the device from the host I am allowing. Is there like ca save all command required? I am trying to use the default pix and telnet password. Do those still work?

View 3 Replies View Related

Cisco Firewall :: ASA 5510 - Website Connection Auto Timeout After 5 Minutes

Oct 15, 2011

Our client tried to a download a real time generated file from a website, the generation process around 5 mins, after 5 mins, the file will be started to download
 
When my client direct connect to internet, the file can be download successfully, but when pass through the ASA 5510 and using the internal IP address, a message something like "Are you sure want to logout from this web page?" appears in Safari after 5 mins, i think the time of the error message appear when a "you can start to download" message send from the server to client, the page session timeout so that make the user cannot download the file from internet as the session is not vaild.
 
I couldn't find any timeout setting in "show runn", is it possible the setting in ASDM? how can I find it and configure it?

View 5 Replies View Related

Cisco Firewall :: ASA 5510 - Show Local-host All Detail Connection / Timeout

Nov 28, 2012

Version: Cisco ASA 5510 8.4(4)1

I've installed cisco asa 5510.

When I "show local-host all detail connection "

Normal situation:

105 myfailover:10.255.255.2/0 NP Identity Ifc:10.255.255.1/0,
idle 0s, uptime 1D14h, timeout 2m0s, bytes 18196822

But I got this output ( timeout - )

[URL]

View 0 Replies View Related

Netgear Wireless Limited Inactivity - Unidentified Network?

Feb 6, 2011

My laptop does not recognize wireless OR the LAN anymore. IT says "Unidentified Network" My laptop connects to the network but the network doesn't connect to the internet. Before I got it and added a password it worked fine! Except it said Limited Connectivity" Here are the system settings for my laptop (I don't think wifi works for my PC either):

Manufacturer: TOSHIBA
Model: Satellite A215
Windows Vista
Rating 3.0
Processor: AMD Turion (tm) 64 x2 Mobile Technology TL-52 1,60 GHz
Memory: 894 MB
System Type: 32-bit Operating System

[code]...

View 11 Replies View Related

Linksys Wireless Adapters :: WET54GS5 Not Accessible After Inactivity?

Apr 15, 2012

I hadn't used this device (version 1) for a couple of years.  After that much time and many changes in my home network, once again I need it to connect a printer.  I pushed the reset button and followed the initial setup directions.  So far so good.
 
Then I followed directions for using it on my network.  Also good.  I can access the bridge's web server and I can send jobs to the printer.
 
My problem is, after a period of inactivity (say, over night) I can no longer access the printer or the bridge.  The only way I have found to get them back is to power-cycle the bridge. Some data ...
 
My router is a WRT320N.  It manages DHCP and reserves a fixed IP address for the bridge.The bridge connects to a wireless network managed by an Apple Airport Extreme 802.11.  It is connected directly to the router.  Yes, I have two WiFi networks.  No, I have not yet tried the bridge on the router's network.The LEDs on the bridge are the same, accessible or not.The printer is an OKI c3400n.

View 3 Replies View Related

Cisco Wireless :: 1260 Root AP De-authenticating WGB Clients After 6 Minutes Of Inactivity

May 27, 2013

i have 2 1260 Access points one is in root mode , one is wgb mode. Authentication is EAPFAST. There are 5 devices connected via WGB bridge to the rest of the network.

- If clients are sending some data , then WGB AP announces this client mac via IAPP to root AP and rest of the network sees them correctly
- If clients are "passive" , then after WBG AP announces them to root AP , they timeout after 6 minutes on root AP and obviously they are not pingable from the rest of the network. The only way to restore connectivity is to ping that device from WGB AP, then WGB AP announces via IAPP to root AP , then and only then they become visible from the rest of the network.

My question is related to this 6 minute timeout on root AP . Is it normal behaviour ?

View 5 Replies View Related

D-Link DIR-600 :: Connection Lost After Inactivity In Wireless / Wired Mode

Jan 18, 2012

I am using InnoMedia MTA6328-1Be2S from Reliance and D-link DIR-600 for sharing internet connection. I have a strange problem here after using internet for sometime..I will not be able to use internet unless I shut down and restart both Innomedia and D-link.I tried changing configurations in D-link but with no luck. I lost the connection no matter I am using wireless or wired mode.I do not know how to login to InnoMedia MTA6328-1Be2S as well.

View 1 Replies View Related

Losing Connection After Every Minute

Aug 29, 2011

I recently moved to a new location and my wireless internet disconnects, literally every minute. My roommate never has any issues with his wireless connection, and this is the first time I've had connection issues with this laptop.The provider is Comcast and it runs through a hard wired/wireless modem (no antennas). Our connection is encrypted. My signal strength is always excellent, but still briefly disconnects with a continuous cycle, as it automatically reconnects.

View 11 Replies View Related

Modem Keeps Disconnecting Every Minute Or So

Oct 21, 2012

Some times it lasts for some hours and then starts disconnecting every minute or so. Sometimes i just turn the computer on and it already starts his routine of disconnections.

[code]....

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Integration With RSA Allow Only One Login Every Minute?

Nov 1, 2011

I have an ACS 5,2.0.26-8 running on VM intergrated with RSA. Users are able to login using their RSA passcode for network management utilizing TACACS. The problem seam to be related with RSA token caching. Once a user login sucessful on device A using current token he can not login with the same token on another device. User must wait for a new token and then he can login again.  Before moving to ACS 5.2 we were using ACS 4.2 (intergrated with the same RSA) and back then ACS 4.2 cache passcode so user where able to login on devices using the same passcode. When the token change user have to use the new one. providing the same functionality like the "Token Card Settings" Durantion option under group properties, to cache token for a specific period. The global option for caching under RSA definition on 5.2 does not solve the problem.

View 4 Replies View Related

Usb Dongle Wifi Connection Last Only A Minute?

Aug 27, 2011

i have usb dongle wifi which i used to connect via wireless router i can connect for a minuite after i plug it and then after a while it cannot browse internet while indicating that is connected as can see on command promt with pinging command "Request timed out" contineously so i going to replug the usb dongle again to connect.

View 1 Replies View Related

Wireless Cuts Out Every Minute For 3-5 Seconds

Jan 7, 2012

im on widows seven and it is a lenovo laptop. It cuts out every minute or so. it say not internet access in my network connections. my router is netgear swell i think. its security type is WPA2-PSK. It mainly happens when i go to play an online game called roblox but also happens when i open up any normal pagge as well. I looked for the WZC but I coudnt find it.

View 1 Replies View Related

Internet Connection Goes Out Every Minute Or So For About 1-2 Seconds

Dec 26, 2012

The problem I am having is my wired internet connection is going out every minute or so and stays out for about 1-2 seconds at a time sometimes it stays out for around 3-4 mins usually twice a day. This problem has been occurring everyday for the past 2 or so years some days it is worse. I have power cycled the modem and router many times, replaced the router, replaced the modem bypassed the router and it always does the same thing. I have gotten cox cable to come out many times, once was to replace the modem, and it conveniently does not have problems when they come then i look stupid. I have showed them the screen shots of the outages from pinging multiple points on the network as shown in the attached screen shot, as you can see in window labeled 1 is a continuous ping of google.com, window 2 is the first hop on the tracert as shown at the bottom of the picture, window 3 is my modem, and window 4 is my router.

As you can see I never lose connection to my router or modem and it is the same when i run tests from other devices. Every time I call them or show them this picture the only response I get is there are no reported outages and to try to reset my modem and router or they can send a tech. When the tech comes there seems to be no problems and I show him the screen shots and he writes it off as peak hour malfunctions even though it does it at non-peak hours as well. Then when he leaves It starts to freak out again I have gone through this scenario at least 3 or 4 times and at this point am getting very frustrated. Even though it is not very noticeable with normal web browsing in gaming and streaming it is a nightmare. I would have already switched service providers if there were any other that service my area.

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved