<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACE: idle timeout on routed connections in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-idle-timeout-on-routed-connections/m-p/1880837#M36621</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After reading a few post about this, I've been trying to test the procedure.&lt;/P&gt;&lt;P&gt;I configured an ACL for a test workstation, connecting to a RServer, simple by going through the ACE, and tried to change the idle_timeout, but can't seem to put it to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I did:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ACL_TCP_IDLE line 8 extended permit tcp host 172.26.112.193 any&lt;/P&gt;&lt;P&gt;access-list ACL_TCP_IDLE line 9 extended permit tcp any host 172.26.112.193&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for test purposes)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; parameter-map type connection TCP_IDLE&lt;/P&gt;&lt;P&gt;&amp;nbsp; set timeout inactivity 15 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all TCP_IDLE_CLASS&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match access-list ACL_TCP_IDLE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this, I tried putting the class into the existing policy, and also tried applying the service policy to the VLAN. Both don't seem to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test 1:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match server-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; class .....&lt;/P&gt;&lt;P&gt;&amp;nbsp; class TCP_IDLE_CLASS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options TCP_IDLE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test 2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match TCP_CONN&lt;/P&gt;&lt;P&gt;&amp;nbsp; class TCP_IDLE_CLASS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options TCP_IDLE&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int VLAN Servers&lt;/P&gt;&lt;P&gt;service-policy input TCP_CONN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What seems stange is than looking to the ACL, it seems not to be active, and there are no hits:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list:ACL_TCP_IDLE, elements: 2, status: NOT-ACTIVE&lt;/P&gt;&lt;P&gt;&amp;nbsp; remark :&lt;/P&gt;&lt;P&gt;access-list ACL_TCP_IDLE line 8 extended permit tcp host 172.26.112.193 any&lt;/P&gt;&lt;P&gt;access-list ACL_TCP_IDLE line 9 extended permit tcp any host 172.26.112.193&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone done something like this ?&lt;/P&gt;</description>
    <pubDate>Thu, 23 Feb 2012 13:48:49 GMT</pubDate>
    <dc:creator>r.portela</dc:creator>
    <dc:date>2012-02-23T13:48:49Z</dc:date>
    <item>
      <title>ACE: idle timeout on routed connections</title>
      <link>https://community.cisco.com/t5/application-networking/ace-idle-timeout-on-routed-connections/m-p/1880837#M36621</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After reading a few post about this, I've been trying to test the procedure.&lt;/P&gt;&lt;P&gt;I configured an ACL for a test workstation, connecting to a RServer, simple by going through the ACE, and tried to change the idle_timeout, but can't seem to put it to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I did:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ACL_TCP_IDLE line 8 extended permit tcp host 172.26.112.193 any&lt;/P&gt;&lt;P&gt;access-list ACL_TCP_IDLE line 9 extended permit tcp any host 172.26.112.193&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for test purposes)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; parameter-map type connection TCP_IDLE&lt;/P&gt;&lt;P&gt;&amp;nbsp; set timeout inactivity 15 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all TCP_IDLE_CLASS&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match access-list ACL_TCP_IDLE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this, I tried putting the class into the existing policy, and also tried applying the service policy to the VLAN. Both don't seem to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test 1:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match server-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; class .....&lt;/P&gt;&lt;P&gt;&amp;nbsp; class TCP_IDLE_CLASS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options TCP_IDLE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test 2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match TCP_CONN&lt;/P&gt;&lt;P&gt;&amp;nbsp; class TCP_IDLE_CLASS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options TCP_IDLE&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int VLAN Servers&lt;/P&gt;&lt;P&gt;service-policy input TCP_CONN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What seems stange is than looking to the ACL, it seems not to be active, and there are no hits:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list:ACL_TCP_IDLE, elements: 2, status: NOT-ACTIVE&lt;/P&gt;&lt;P&gt;&amp;nbsp; remark :&lt;/P&gt;&lt;P&gt;access-list ACL_TCP_IDLE line 8 extended permit tcp host 172.26.112.193 any&lt;/P&gt;&lt;P&gt;access-list ACL_TCP_IDLE line 9 extended permit tcp any host 172.26.112.193&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone done something like this ?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2012 13:48:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-idle-timeout-on-routed-connections/m-p/1880837#M36621</guid>
      <dc:creator>r.portela</dc:creator>
      <dc:date>2012-02-23T13:48:49Z</dc:date>
    </item>
    <item>
      <title>ACE: idle timeout on routed connections</title>
      <link>https://community.cisco.com/t5/application-networking/ace-idle-timeout-on-routed-connections/m-p/1880838#M36622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACL output you are getting is normal. An ACL will only show as active and log hits when it's directly applied on an interface to allow/deny traffic, not when it's used to define a class-map. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At first sight, the configuration you are using seems to be fine. How are you testing it? You should start by using the "show service-policy" command to see if this class is getting any hits. Then, if you see hits in this class, you should establish a connection and keep it idle, measuring the time it takes for it to be removed from the connection table. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Feb 2012 09:11:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-idle-timeout-on-routed-connections/m-p/1880838#M36622</guid>
      <dc:creator>Daniel Arrondo Ostiz</dc:creator>
      <dc:date>2012-02-27T09:11:14Z</dc:date>
    </item>
  </channel>
</rss>

