<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to set VPN idle timeout to NONE on cisco FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/4683148#M1093244</link>
    <description>&lt;P&gt;i think you are referring to RAVPN and not S2S?&lt;/P&gt;</description>
    <pubDate>Thu, 08 Sep 2022 02:29:35 GMT</pubDate>
    <dc:creator>Herald Sison</dc:creator>
    <dc:date>2022-09-08T02:29:35Z</dc:date>
    <item>
      <title>Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3952322#M935607</link>
      <description>&lt;P&gt;Does anyone know how to change the default value of&amp;nbsp; vpn-idle-timeout 30 on Cisco FMC or Cisco FTD CLI. I have just configured a site-to-site VPN and it goes down every 30 mins on Cisco FMC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked almost everywhere on the Internet, don't know why it's so difficult on Cisco FTD but easy on Cisco ASA.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:39:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3952322#M935607</guid>
      <dc:creator>shinerner</dc:creator>
      <dc:date>2020-02-21T17:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3952427#M935609</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Are you facing this issue continuously even when the L2L session is active...???&lt;/P&gt;&lt;P&gt;I couldn't find any direct way to change the idle timeout value in FTD. Did you try by changing this with FLEX CONFIG.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2019 07:02:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3952427#M935609</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2019-11-04T07:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3952624#M935612</link>
      <description>Thanks Abheesh, It happens every time, the tunnel only stays UP for 30mins, and when I check "show crypto ikev2 sa or show crypto ipsec sa", it says NO active Ikev2 or NO active ipsec. I tried the FLEX CONFIG, No difference. I don't know why Cisco made it that way.</description>
      <pubDate>Mon, 04 Nov 2019 13:26:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3952624#M935612</guid>
      <dc:creator>shinerner</dc:creator>
      <dc:date>2019-11-04T13:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3952796#M935615</link>
      <description>&lt;P&gt;First, vpn-idle-timeout should only take effect if there is no traffic on the site-site VPN for the specified period.&lt;/P&gt;
&lt;P&gt;Flexconfig is the correct place to change this parameter (as of 6.5 at least).&lt;/P&gt;
&lt;P&gt;If you've verified that you have it set (double check that you are using the expected group-policy) and you are still seeing timeouts even though you have not met your specified idle timeout value, it may be happening due to a setting on the remote end.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2019 16:44:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3952796#M935615</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-11-04T16:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3952831#M935617</link>
      <description>Hi Marvin, Thanks for shedding more light. The vpn-idle-timeout was set to 30 (default from Cisco), and there is NO traffic, I only did a PING trace over the tunnel, among the three Cisco FTDs, all having same settings, and found out the tunnel is down after 30 mins. My Cisco FTD run 6.2.3 version, and I couldn't find anything related to vpn idle time on the Flexconfig. Hopefully works when traffics are migrated to these FTDs. Thanks so much for your time.</description>
      <pubDate>Mon, 04 Nov 2019 17:19:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3952831#M935617</guid>
      <dc:creator>shinerner</dc:creator>
      <dc:date>2019-11-04T17:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3952847#M935619</link>
      <description>&lt;P&gt;With no traffic we would expect the tunnel to tear down after 30 minutes. That's normal behavior and by design.&lt;/P&gt;
&lt;P&gt;As long as there is traffic, it would normally rekey before the lifetime expires and stay up effectively forever.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2019 17:50:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3952847#M935619</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-11-04T17:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3988813#M935621</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;gt;With no traffic we would expect the tunnel to tear down after 30 minutes. That's normal behavior and by design.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a TAC case open as we speak on this subject, and Cisco informs me to change the behavior with some advanced configuration. That means changing the timeout values.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason I think people are getting frustrated by this is the error handling in FMC. Almost all events that are related to IPsec timeout or peer disconnect and so on, are all comming up as "critical" errors in red boxes. Why normal behavior are marked this way I dont understand. When having a lot of IPsec tunnels the FTD is marked with critial error 24/7.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will get back to this post after hearing more from the TAC people.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 11:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3988813#M935621</guid>
      <dc:creator>Jon Are Endrerud</dc:creator>
      <dc:date>2019-11-25T11:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3988843#M935622</link>
      <description>&lt;P&gt;Thanks for the update.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 12:09:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3988843#M935622</guid>
      <dc:creator>shinerner</dc:creator>
      <dc:date>2019-11-25T12:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3988876#M935623</link>
      <description>&lt;P&gt;Response from TAC:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Yes, this message is displayed as ‘critical’. However we cannot change the log/alerts settings for VPN idle time-out message from “Critical” to “Informational”.
This is the limitation of the FTD. This limitation may be fixed in future software code. But cannot confirm the ETA.&lt;/PRE&gt;</description>
      <pubDate>Mon, 25 Nov 2019 13:09:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/3988876#M935623</guid>
      <dc:creator>Jon Are Endrerud</dc:creator>
      <dc:date>2019-11-25T13:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/4043655#M1067622</link>
      <description>&lt;P&gt;For vpn-idle-timeout none I had to add a group policy via Flex Config. DO NOT add the access-list but in the group policy I had to add the&amp;nbsp;&amp;nbsp;user-authentication-idle-timeout none&lt;/P&gt;&lt;P&gt;group-polic Group-Policy-X.X.X.X internal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;group-polic Group-Policy-X.X.X.X attributes&lt;/P&gt;&lt;P&gt;&amp;nbsp;vpn-idle-timeout none&lt;/P&gt;&lt;P&gt;vpn-idle-timeout alert-interval 1&lt;/P&gt;&lt;P&gt;vpn-session-timeout none&lt;/P&gt;&lt;P&gt;vpn-session-timeout alert-interval 1&lt;/P&gt;&lt;P&gt;vpn-filter none&lt;/P&gt;&lt;P&gt;vpn-tunnel-protocol ikev1 ikev2&lt;/P&gt;&lt;P&gt;user-authentication-idle-timeout none&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/security/firepower/migration-tool/migration-guide/s2s_ikev1_psk.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/security/firepower/migration-tool/migration-guide/s2s_ikev1_psk.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 18:53:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/4043655#M1067622</guid>
      <dc:creator>davidmendozajr</dc:creator>
      <dc:date>2020-03-10T18:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/4043661#M1067624</link>
      <description>&lt;P&gt;In order for not the tunnel get down. why dont you sent up a continuous ping from your defined interested traffic from your end to other end defined interested traffic. this is one of the way to keep the tunnel up and running.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 18:57:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/4043661#M1067624</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2020-03-10T18:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/4073751#M1069506</link>
      <description>&lt;P&gt;I'm running 6.5.0.4 (build 57)&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I was able to go to Objects &amp;gt; VPN &amp;gt; Group Policy &amp;gt; DftGrpPolicy &amp;gt; Advanced &amp;gt; Session Settings &amp;gt; Idle Timeout &amp;gt; erase the "30" and it will fill the black with "none" by default.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 21:36:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/4073751#M1069506</guid>
      <dc:creator>Hyperion0000</dc:creator>
      <dc:date>2020-04-24T21:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/4683148#M1093244</link>
      <description>&lt;P&gt;i think you are referring to RAVPN and not S2S?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 02:29:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/4683148#M1093244</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-09-08T02:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to set VPN idle timeout to NONE on cisco FTD</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/5373311#M1124587</link>
      <description>&lt;P&gt;Updating this old thread:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;In recent versions of FMC you can set the VPN Idle timeout per S2S VPN under the Advanced &amp;gt; Tunnel &amp;gt; Session Settings. You can also set it globally for the default group-policy under Object Management &amp;gt; VPN &amp;gt;Group Policy and edit DfltGrpPolicy.&lt;/P&gt;
&lt;P&gt;If the VPN is established, you will need to clear the peer association and allow it to rebuild for the change to take effect.&lt;BR /&gt;Verification of the active setting can be done via cli using "&lt;SPAN&gt;show vpn-sessiondb detail l2l filter ipaddress&lt;/SPAN&gt;&amp;nbsp;&amp;lt;address of peer&amp;gt;" and check near the bottom for the value of "&lt;SPAN&gt;Idle Time Out&lt;/SPAN&gt;".&lt;/P&gt;
&lt;P&gt;You can also pull up the output via Insights &amp;amp; Reports &amp;gt; Site-to-Site VPN Dashboard (available in current FMC versions).&lt;BR /&gt;&lt;BR /&gt;NOTE: The Cisco guidance in the following document is obsolete. I have provided feedback to them so hopefully it will be updated.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/217436-disable-ftd-site-to-site-vpn-idle-timeou.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/217436-disable-ftd-site-to-site-vpn-idle-timeou.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2026 14:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-set-vpn-idle-timeout-to-none-on-cisco-ftd/m-p/5373311#M1124587</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2026-02-27T14:51:35Z</dc:date>
    </item>
  </channel>
</rss>

