<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UDP timeout on FWSM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/udp-timeout-on-fwsm/m-p/1931812#M457950</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not have any policy-map applied that changes the UDP/123 timeouts, it might be a bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCso29047 Bug Details&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="5" cellspacing="2" style="color: #000000; font-family: Arial, Helvetica, sans-serif; text-align: -webkit-auto; background-color: #ffffff;" width="100%"&gt;&lt;TBODY&gt;&lt;TR style="vertical-align: top;"&gt;&lt;TD colspan="2" style="font-size: 12px; padding: 8px;"&gt;&lt;STRONG&gt;set random-seq-number disable in MPC affects on UDP/ICMP conn timeout&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="vertical-align: top;"&gt;&lt;TD style="padding-left: 8px; padding-right: 8px; font-size: 12px; padding-bottom: 8px;" valign="top"&gt;&lt;STRONG&gt;Symptom:&lt;/STRONG&gt;&lt;P&gt;&lt;/P&gt;When random-sequence-number is disabled in policy-map, this causes the UDP connection timeout set to 60 minutes when global timeout for UDP/ ICMP is set to two minutes.&lt;P&gt;&lt;/P&gt;&lt;STRONG&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;:&lt;/STRONG&gt;&lt;P&gt;&lt;/P&gt;Random-sequence-number is disabled in policy-map.&lt;P&gt;&lt;/P&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;P&gt;&lt;/P&gt;Do not disable random-sequence-number feature&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is not the case, you can try opening a TAC case.&lt;/P&gt;&lt;P&gt;In my opinion I would upgrade the software first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Mar 2012 06:51:10 GMT</pubDate>
    <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
    <dc:date>2012-03-20T06:51:10Z</dc:date>
    <item>
      <title>UDP timeout on FWSM</title>
      <link>https://community.cisco.com/t5/network-security/udp-timeout-on-fwsm/m-p/1931811#M457946</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an issue where udp idle sessions are not being closed after the configured 2 minute timeout, but instead staying open for 1 hour. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FWSM Version&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;FWSM Firewall Version 4.0(12)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Timeout configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Connections&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;fwsm# show conn&lt;/P&gt;&lt;P&gt;UDP InterfaceA 192.168.1.1:123 InterfaceB 192.168.2.1:64795 idle 0:28:16 Bytes 376 FLAGS -&lt;/P&gt;&lt;P&gt;UDP InterfaceA 192.168.1.1:123 InterfaceB 192.168.2.1:53936 idle 0:18:15 Bytes 376 FLAGS -&lt;/P&gt;&lt;P&gt;UDP InterfaceA 192.168.1.1:123 InterfaceB 192.168.2.1:54244 idle 0:58:18 Bytes 376 FLAGS -&lt;/P&gt;&lt;P&gt;UDP InterfaceA 192.168.1.1:123 InterfaceB 192.168.2.1:52696 idle 0:38:17 Bytes 376 FLAGS -&lt;/P&gt;&lt;P&gt;UDP InterfaceA 192.168.1.1:123 InterfaceB 192.168.2.1:50206 idle 0:08:15 Bytes 376 FLAGS - &lt;/P&gt;&lt;P&gt;UDP InterfaceA 192.168.1.1:123 InterfaceB 192.168.2.1:54245 idle 0:48:18 Bytes 376 FLAGS -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: 192.168.2.1 is a PC polling an NTP (192.168.1.1) server every 10 minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:44:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/udp-timeout-on-fwsm/m-p/1931811#M457946</guid>
      <dc:creator>inthemix1</dc:creator>
      <dc:date>2019-03-11T22:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: UDP timeout on FWSM</title>
      <link>https://community.cisco.com/t5/network-security/udp-timeout-on-fwsm/m-p/1931812#M457950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not have any policy-map applied that changes the UDP/123 timeouts, it might be a bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCso29047 Bug Details&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="5" cellspacing="2" style="color: #000000; font-family: Arial, Helvetica, sans-serif; text-align: -webkit-auto; background-color: #ffffff;" width="100%"&gt;&lt;TBODY&gt;&lt;TR style="vertical-align: top;"&gt;&lt;TD colspan="2" style="font-size: 12px; padding: 8px;"&gt;&lt;STRONG&gt;set random-seq-number disable in MPC affects on UDP/ICMP conn timeout&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="vertical-align: top;"&gt;&lt;TD style="padding-left: 8px; padding-right: 8px; font-size: 12px; padding-bottom: 8px;" valign="top"&gt;&lt;STRONG&gt;Symptom:&lt;/STRONG&gt;&lt;P&gt;&lt;/P&gt;When random-sequence-number is disabled in policy-map, this causes the UDP connection timeout set to 60 minutes when global timeout for UDP/ ICMP is set to two minutes.&lt;P&gt;&lt;/P&gt;&lt;STRONG&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;:&lt;/STRONG&gt;&lt;P&gt;&lt;/P&gt;Random-sequence-number is disabled in policy-map.&lt;P&gt;&lt;/P&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;P&gt;&lt;/P&gt;Do not disable random-sequence-number feature&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is not the case, you can try opening a TAC case.&lt;/P&gt;&lt;P&gt;In my opinion I would upgrade the software first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2012 06:51:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/udp-timeout-on-fwsm/m-p/1931812#M457950</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2012-03-20T06:51:10Z</dc:date>
    </item>
  </channel>
</rss>

