<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic UDP timeout ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/udp-timeout-asa/m-p/1837897#M460331</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-There is no need for a connection to be idle in order to be closed, I mean there are other facts that will turn the connection down, also remember that the ASAS can statefully inspect TCP/UDP (by default)&amp;nbsp; and ICMP if configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2-Yes, they appear there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3-Correct, if you have a timeout 0 0 that will cause some issues ( No ports available if PAT is being used,etc) as none of the connections are being closed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 01 Feb 2012 05:29:02 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-02-01T05:29:02Z</dc:date>
    <item>
      <title>UDP timeout ASA</title>
      <link>https://community.cisco.com/t5/network-security/udp-timeout-asa/m-p/1837896#M460330</link>
      <description>&lt;P&gt;Hi all, just have a few questions about UDP timeout.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. From what I understand connectionless protocols such as UDP have to idle out to be closed, as their is no connection information, is this correct?&lt;/P&gt;&lt;P&gt; 2. Do these connections appear in the connection/State table?&amp;nbsp; &lt;/P&gt;&lt;P&gt;3. If you disable the UDP timeout on the firewall, doesnt this mean that the UDP sessions could fill up the state table as no of the connections woulf time out?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:21:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/udp-timeout-asa/m-p/1837896#M460330</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2019-03-11T22:21:45Z</dc:date>
    </item>
    <item>
      <title>UDP timeout ASA</title>
      <link>https://community.cisco.com/t5/network-security/udp-timeout-asa/m-p/1837897#M460331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-There is no need for a connection to be idle in order to be closed, I mean there are other facts that will turn the connection down, also remember that the ASAS can statefully inspect TCP/UDP (by default)&amp;nbsp; and ICMP if configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2-Yes, they appear there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3-Correct, if you have a timeout 0 0 that will cause some issues ( No ports available if PAT is being used,etc) as none of the connections are being closed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Feb 2012 05:29:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/udp-timeout-asa/m-p/1837897#M460331</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-01T05:29:02Z</dc:date>
    </item>
    <item>
      <title>UDP timeout ASA</title>
      <link>https://community.cisco.com/t5/network-security/udp-timeout-asa/m-p/1837898#M460333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;EM&gt;"There is no need for a connection to be idle in order to be closed, I&amp;nbsp; mean there are other facts that will turn the connection down,"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like what?&amp;nbsp; There is no state information so how does the firewall know the connection is done with?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Feb 2012 13:07:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/udp-timeout-asa/m-p/1837898#M460333</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2012-02-01T13:07:49Z</dc:date>
    </item>
    <item>
      <title>UDP timeout ASA</title>
      <link>https://community.cisco.com/t5/network-security/udp-timeout-asa/m-p/1837899#M460334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I did not explain my self on the last post I was talking about the behavior of the ASA with a stateful protocol, with the protocol udp the stateful firewall will use the &lt;STRONG style="color: #000000; font-family: sans-serif; line-height: 19px; text-align: -webkit-auto; background-color: #ffffff;"&gt;hole punching as the &lt;/STRONG&gt;&lt;STRONG style="color: #000000; font-family: sans-serif; line-height: 19px; text-align: -webkit-auto; background-color: #ffffff;"&gt;method to detect or keep track of the connection.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Such sessions usually get the ESTABLISHED state immediately after the first packet is seen by the firewal&lt;/P&gt;&lt;P&gt;Sessions in connectionless protocols (like UDP) can only end by time-out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the ASA do keep track of these connections as I mention before.&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #000000; font-family: sans-serif; line-height: 19px; text-align: -webkit-auto; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Feb 2012 14:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/udp-timeout-asa/m-p/1837899#M460334</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-01T14:25:21Z</dc:date>
    </item>
  </channel>
</rss>

