<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Recommended embryonic connection timeout in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/recommended-embryonic-connection-timeout/m-p/1933164#M457190</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank u very much, useful elements for my formula...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Apr 2012 18:01:22 GMT</pubDate>
    <dc:creator>Diego Zuniga</dc:creator>
    <dc:date>2012-04-16T18:01:22Z</dc:date>
    <item>
      <title>Recommended embryonic connection timeout</title>
      <link>https://community.cisco.com/t5/network-security/recommended-embryonic-connection-timeout/m-p/1933162#M457186</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to set up the proper value for a embryonic connection timeout on a Cisco PIX running 7.2(1). So far I have read some documents that describe how to set up the value but nothing concrete about what factors must be considered in order to set up this value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to this URL:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/224711" target="_blank"&gt;https://supportforums.cisco.com/thread/224711&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The FWSM was using a default embryonic connection timeout value of 5 secs (2.2 code and earlier) but on newer codes is using 20 secs as default. The point is, what did Cisco consider to use this value?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to this URL:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2032754" target="_blank"&gt;https://supportforums.cisco.com/thread/2032754&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They say the value is relative to the servers' OS, for example Windows has a timeout value of 21 secs, but some people consider 21 secs is too much time for an attacker to create a SYN Flood attack and successfully affect the servers behind the ASA/PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I personally agree with the fact that is 21 secs is too much time so I accessed my websites from an external location using very low connections (128Kbps download/32Kbps upload) and fully loaded (about 90% of BW downloading a file) and I noticed the value for the handshake (SYN, SYN/ACK, ACK) was around 3 secs using wireshark captures. So I consider the value should be around 5 secs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASA config guide, Cisco defaults this value to 30 secs, on the ACE 4700 appliance config guide, Cisco defaults this value to 5 secs&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://es.scribd.com/doc/51349206/424/config-parammap-conn-set-tcp-timeout" target="_blank"&gt;http://es.scribd.com/doc/51349206/424/config-parammap-conn-set-tcp-timeout&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_connlimits.html#wp1080774" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_connlimits.html#wp1080774&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some Cisco articles suggest 45 secs for the timeout value.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00809763ea.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00809763ea.shtml&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My main concern is, am I missing something? Based on wireshark captures I got 5 secs, but this value is too much lower than the Cisco defaults for ASA and FWSM. Besides, some articles suggest 45 secs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if the tests I have done so far will be enough or I should consider additional elements in my formula to get a proper value, if someone could suggest me additional elements I can test to adjust my formula I will really appreciate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time and opinions&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:52:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommended-embryonic-connection-timeout/m-p/1933162#M457186</guid>
      <dc:creator>Diego Zuniga</dc:creator>
      <dc:date>2019-03-11T22:52:22Z</dc:date>
    </item>
    <item>
      <title>Recommended embryonic connection timeout</title>
      <link>https://community.cisco.com/t5/network-security/recommended-embryonic-connection-timeout/m-p/1933163#M457188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Diego,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me jump into this one as per Rick Troyo request hehe &lt;SPAN __jive_emoticon_name="laugh" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First I'll start with timeout change on the FWSM, this was due to CSCeg02866 &lt;/P&gt;&lt;P&gt;Cisco changed this thinking on oversubscribed links for example, this is because the timer starts&amp;nbsp; when the device sees the first SYN and is not reset for the&amp;nbsp; retransmitted SYN and as you can imagine there are many reasons why a packet can be dropped thus the SYN must be retransmitted that's just how TCP works but like I said the timer will be already counting down. If the SYN+ACK comes after the timeout has&amp;nbsp; expired, the connection is removed an the packet is dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bottom line in your formula you are not taking into consideration delays or network problems you might find over "X" environment, your tests show 5 seconds will be good but what if you go to another country and try to access the same server? what if you have to go through a VPN? what if your ISP is having some sort of connectivity problems?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2012 22:48:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommended-embryonic-connection-timeout/m-p/1933163#M457188</guid>
      <dc:creator>Gustavo Medina</dc:creator>
      <dc:date>2012-04-13T22:48:07Z</dc:date>
    </item>
    <item>
      <title>Recommended embryonic connection timeout</title>
      <link>https://community.cisco.com/t5/network-security/recommended-embryonic-connection-timeout/m-p/1933164#M457190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank u very much, useful elements for my formula...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2012 18:01:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/recommended-embryonic-connection-timeout/m-p/1933164#M457190</guid>
      <dc:creator>Diego Zuniga</dc:creator>
      <dc:date>2012-04-16T18:01:22Z</dc:date>
    </item>
  </channel>
</rss>

