<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I just want to know concept in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034763#M135909</link>
    <description>&lt;P&gt;I just want to know concept of timeout connection in my asa.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What you say before, "Accordingly it remove the record of connection from its connection table" , we focus to "connection table", how can i see the connection table in my asa? whats the command?&lt;/P&gt;</description>
    <pubDate>Sun, 07 May 2017 13:16:04 GMT</pubDate>
    <dc:creator>williammanurung</dc:creator>
    <dc:date>2017-05-07T13:16:04Z</dc:date>
    <item>
      <title>What the function configure Connection timeout on ASA?</title>
      <link>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034759#M135905</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I just want to know, what the exactly function command on below my ASA 5585-X:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;timeout xlate 3:00:00&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;timeout pat-xlate 0:00:30&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;timeout floating-conn 0:00:00&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;What ASA will do after connection timeout?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;William&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:18:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034759#M135905</guid>
      <dc:creator>williammanurung</dc:creator>
      <dc:date>2019-03-12T09:18:58Z</dc:date>
    </item>
    <item>
      <title>After a timeout expires for a</title>
      <link>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034760#M135906</link>
      <description>&lt;P&gt;After a timeout expires for a given xlate or connection, the ASA will either release the xlate or the drop the connection record from its internal tables and free up the memory and any other resources that it was using.&lt;/P&gt;
&lt;P&gt;For xlates, that means any new traffic needing to be NATted will re-establish an xlate.&lt;/P&gt;
&lt;P&gt;For connections, it means that the connection state will need to be re-established for any subsequent traffic. An active connection (or flow for stateless traffic like udp and icmp) means that the return traffic bypasses ACLs since it is know to be part of an existing allowed flow.&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 09:08:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034760#M135906</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-04T09:08:24Z</dc:date>
    </item>
    <item>
      <title>what the meaning of "timeout</title>
      <link>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034761#M135907</link>
      <description>&lt;P&gt;what the meaning of "timeout expires"?&lt;/P&gt;
&lt;P&gt;Is there end to end close connection?&lt;/P&gt;
&lt;P&gt;Can you give me another example?&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 07:34:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034761#M135907</guid>
      <dc:creator>williammanurung</dc:creator>
      <dc:date>2017-05-05T07:34:17Z</dc:date>
    </item>
    <item>
      <title>"timeout expires" means that</title>
      <link>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034762#M135908</link>
      <description>&lt;P&gt;"timeout expires" means that the idle time for a given connection has counted down to 0:00:00 and is not longer considered active by the firewall. Accordingly it remove the record of connection from its connection table.&lt;/P&gt;
&lt;P&gt;Only the two endpoints of an existing connection can close the connection. The ASA does not intervene and send a TCP FIN or anything like that for an existing connection table record that has become idle and had its timeout expired.&lt;/P&gt;
&lt;P&gt;What is your reason for asking?&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2017 09:28:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034762#M135908</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-05T09:28:57Z</dc:date>
    </item>
    <item>
      <title>I just want to know concept</title>
      <link>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034763#M135909</link>
      <description>&lt;P&gt;I just want to know concept of timeout connection in my asa.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What you say before, "Accordingly it remove the record of connection from its connection table" , we focus to "connection table", how can i see the connection table in my asa? whats the command?&lt;/P&gt;</description>
      <pubDate>Sun, 07 May 2017 13:16:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034763#M135909</guid>
      <dc:creator>williammanurung</dc:creator>
      <dc:date>2017-05-07T13:16:04Z</dc:date>
    </item>
    <item>
      <title>You can show the connection</title>
      <link>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034764#M135910</link>
      <description>&lt;P&gt;You can show the connection table with the command "show conn".&lt;/P&gt;</description>
      <pubDate>Sun, 07 May 2017 13:38:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034764#M135910</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-07T13:38:13Z</dc:date>
    </item>
    <item>
      <title>Just to add, when a</title>
      <link>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034765#M135911</link>
      <description>&lt;P&gt;Just to add, when a connection is idle, the connection is removed from connection table after idle timeout expires as defined by&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;and the xlate timer kicks in once the connection is removed. So, the xlate is still present even when the connection is removed.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;I&gt;&lt;EM&gt;&lt;STRONG&gt;timeout xlate 3:00:00&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;timeout pat-xlate 0:00:30&lt;/STRONG&gt;&lt;/EM&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As an example, when a connection goes into idle state, the connection entry is removed after 1 hour(assuming above config) and post 1 hour, the xlate will be cleared after 30 seconds or 3 hour depending upon if its a nat or pat.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;A link that talks more:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/document/88256/understanding-xlate-and-conn-idle-and-timeout-values-through-example&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;BR /&gt;-AJ&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;I&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;I&gt;&lt;/I&gt;&lt;/B&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 07 May 2017 16:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034765#M135911</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2017-05-07T16:57:24Z</dc:date>
    </item>
    <item>
      <title>So, the meaning of the idle</title>
      <link>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034766#M135912</link>
      <description>&lt;P&gt;So, the meaning of the idle connection is the end to end connect but no packet transfer?&lt;/P&gt;
&lt;P&gt;What minimum packet have to transfer to be idle timer back to 00:00:00?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2017 06:17:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034766#M135912</guid>
      <dc:creator>williammanurung</dc:creator>
      <dc:date>2017-05-08T06:17:45Z</dc:date>
    </item>
    <item>
      <title>So, the meaning of the idle</title>
      <link>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034767#M135914</link>
      <description>&lt;P&gt;So, the meaning of the idle connection is the end to end connect but no packet transfer?&lt;/P&gt;
&lt;P&gt;&lt;I&gt;yes&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What minimum packet have to transfer to be idle timer back to 00:00:00?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;there is no minimum packet transfer. The logic is that if there is an attempt from either side to transfer any finite number of bytes, it will make the restart the idle timeout value.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;HTH&lt;/I&gt;&lt;/P&gt;
&lt;P&gt;&lt;I&gt;-AJ&lt;/I&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2017 12:18:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-the-function-configure-connection-timeout-on-asa/m-p/3034767#M135914</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2017-05-08T12:18:24Z</dc:date>
    </item>
  </channel>
</rss>

