<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA 8.4.3: Infinite SunRPC inspection timeout possible? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-8-4-3-infinite-sunrpc-inspection-timeout-possible/m-p/1915206#M456948</link>
    <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an ASA5520 firewall which is used to secure some servers in the office. One server in the DMZ is accessing a NFS share on a higher security-level interface.&lt;/P&gt;&lt;P&gt;To make this work, we have allowed port 111 and enabled sunrpc-server as well as protocol inspection.&lt;/P&gt;&lt;P&gt;So far so good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The mount and operation works fine but after &amp;lt;timeout&amp;gt; the session on the ASA gets closed.&lt;/P&gt;&lt;P&gt;This happens even if there is continous traffic via NFS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The timeout setting seems to be an overall timeout for the translation and not only an idle-timeout (which would make sense)&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout&amp;nbsp; Idle time after which the hole for the SUNRPC service traffic will&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; be closed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I make the translation permanent, NOT timeouting after a fixed time? &lt;/P&gt;&lt;P&gt;Configuring 00:00:00 as timeout setting is not accepted in the CLI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you and best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bernhard&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:54:57 GMT</pubDate>
    <dc:creator>Bernhard Roth</dc:creator>
    <dc:date>2019-03-11T22:54:57Z</dc:date>
    <item>
      <title>Cisco ASA 8.4.3: Infinite SunRPC inspection timeout possible?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-8-4-3-infinite-sunrpc-inspection-timeout-possible/m-p/1915206#M456948</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an ASA5520 firewall which is used to secure some servers in the office. One server in the DMZ is accessing a NFS share on a higher security-level interface.&lt;/P&gt;&lt;P&gt;To make this work, we have allowed port 111 and enabled sunrpc-server as well as protocol inspection.&lt;/P&gt;&lt;P&gt;So far so good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The mount and operation works fine but after &amp;lt;timeout&amp;gt; the session on the ASA gets closed.&lt;/P&gt;&lt;P&gt;This happens even if there is continous traffic via NFS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The timeout setting seems to be an overall timeout for the translation and not only an idle-timeout (which would make sense)&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout&amp;nbsp; Idle time after which the hole for the SUNRPC service traffic will&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; be closed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I make the translation permanent, NOT timeouting after a fixed time? &lt;/P&gt;&lt;P&gt;Configuring 00:00:00 as timeout setting is not accepted in the CLI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you and best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bernhard&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:54:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-8-4-3-infinite-sunrpc-inspection-timeout-possible/m-p/1915206#M456948</guid>
      <dc:creator>Bernhard Roth</dc:creator>
      <dc:date>2019-03-11T22:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 8.4.3: Infinite SunRPC inspection timeout possible</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-8-4-3-infinite-sunrpc-inspection-timeout-possible/m-p/1915207#M456949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to be possible&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco material states the following for your software version&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;timeout&lt;/STRONG&gt; {&lt;STRONG&gt;conn&lt;/STRONG&gt; |&lt;STRONG&gt; floating-conn&lt;/STRONG&gt; | &lt;STRONG&gt;h225&lt;/STRONG&gt; | &lt;STRONG&gt;h323&lt;/STRONG&gt; | &lt;STRONG&gt;half-closed&lt;/STRONG&gt; | &lt;STRONG&gt;icmp&lt;/STRONG&gt; | &lt;STRONG&gt;mgcp&lt;/STRONG&gt; | &lt;STRONG&gt;mgcp-pat&lt;/STRONG&gt; | &lt;STRONG&gt;pat-xlate&lt;/STRONG&gt; |&amp;nbsp; &lt;STRONG&gt;sip&lt;/STRONG&gt; | &lt;STRONG&gt;sip-disconnect&lt;/STRONG&gt; | &lt;STRONG&gt;sip-invite&lt;/STRONG&gt; | &lt;STRONG&gt;sip_media &lt;/STRONG&gt;|&lt;STRONG&gt; sip-provisional-media&lt;/STRONG&gt; | &lt;STRONG&gt;sunrpc&lt;/STRONG&gt; |&amp;nbsp; &lt;STRONG&gt;tcp-proxy-reassembly &lt;/STRONG&gt;|&lt;STRONG&gt; udp&lt;/STRONG&gt; |&lt;STRONG&gt; xlate&lt;/STRONG&gt;} &lt;EM style="font-style: italic;"&gt;hh&lt;/EM&gt;:&lt;EM style="font-style: italic;"&gt;mm&lt;/EM&gt;:&lt;EM&gt;ss &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" id="wp1569882table1569880" style="width: 80%;"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P&gt; &lt;STRONG&gt;sunrpc&lt;/STRONG&gt; &lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp1569949"&gt;&lt;/A&gt;&lt;P&gt; Specifies the idle time after which a SUNRPC slot will be closed,&amp;nbsp; between 0:1:0 and 1193:0:0. The default is 10 minutes (0:10:0). &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Use 0 to never time out a connection&lt;/STRONG&gt;&lt;/SPAN&gt;. &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 16:51:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-8-4-3-infinite-sunrpc-inspection-timeout-possible/m-p/1915207#M456949</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-04-17T16:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 8.4.3: Infinite SunRPC inspection timeout possible</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-8-4-3-infinite-sunrpc-inspection-timeout-possible/m-p/1915208#M456950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I saw that but how do the settings correlate to each other?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Per sunrpc-server timeout setting e.g.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;sunrpc-server intdmz 10.1.2.3 255.255.255.255 service 100005 protocol TCP port 111 timeout 02:00:00&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the global setting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;timeout sunrpc 0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my understanding it would make far more sense to have the global setting as default but with the ability to specify an optional timeout, for example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global timeout set to 30 minutes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;timeout sunrpc 00:30:00&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Protocol inspection without timeout setting (uses global value, RFE)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;sunrpc-server intdmz 10.1.2.3 255.255.255.255 service 100005 protocol TCP port 111&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Protocol inspection with individual timeout setting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;sunrpc-server intdmz 10.1.2.3 255.255.255.255 service 100005 protocol TCP port 111 timeout 02:00:00&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Protocol inspection with infinite timeout setting (RFE)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;sunrpc-server intdmz 10.1.2.3 255.255.255.255 service 100005 protocol TCP port 111 timeout 00:00:00&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will not break any existing configurations from previous ASA software releases.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feedback welcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bernhard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 17:25:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-8-4-3-infinite-sunrpc-inspection-timeout-possible/m-p/1915208#M456950</guid>
      <dc:creator>Bernhard Roth</dc:creator>
      <dc:date>2012-04-17T17:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 8.4.3: Infinite SunRPC inspection timeout possible</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-8-4-3-infinite-sunrpc-inspection-timeout-possible/m-p/1915209#M456951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some additional informations:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just configured "timeout sunrpc 0" and in the sunrpc-server statement a timeout of 10 minutes.&lt;/P&gt;&lt;P&gt;After exactly 10 minutes the client reports error messages and the session on the ASA is closed ("sh sun ac")&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What to do?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 18:27:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-8-4-3-infinite-sunrpc-inspection-timeout-possible/m-p/1915209#M456951</guid>
      <dc:creator>Bernhard Roth</dc:creator>
      <dc:date>2012-04-17T18:27:31Z</dc:date>
    </item>
  </channel>
</rss>

