<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM idle connection timeout issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807328#M491120</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That seems to be it the database connectivity seems to be matching the global policy now , well I did not make it unlimited for the global_policy however limited it to 6hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know whether you have a standarad list of connections categorised as secondary flows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your help .you have a great day &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Dec 2011 15:12:31 GMT</pubDate>
    <dc:creator>Siju S</dc:creator>
    <dc:date>2011-12-19T15:12:31Z</dc:date>
    <item>
      <title>FWSM idle connection timeout issues</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807320#M491109</link>
      <description>&lt;P&gt;The service policy appied to set the idle connection timeout does not apply for a particular traffic destined for SQL net connections . However any other TCP ports are identified . Does that mean that Sql Net connections idle timeout can be altered only by the global option &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer to :&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide/protct_f.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide/protct_f.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1060237" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;Note &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="6" /&gt;This command does not affect&amp;nbsp; secondary connections created by an inspection engine. For example, you&amp;nbsp; cannot change the connection settings for secondary flows like SQL*Net,&amp;nbsp; FTP data flows, and so on using the &lt;STRONG&gt;set connection&amp;nbsp; timeout &lt;/STRONG&gt;command. For these connections, use the global&lt;STRONG&gt; timeout conn &lt;/STRONG&gt;command to change the idle time. Note&amp;nbsp; that the &lt;STRONG&gt;timeout conn&lt;/STRONG&gt; command affects &lt;EM&gt;all&lt;/EM&gt; traffic flows unless you otherwise use the &lt;STRONG&gt;set connection timeout&lt;/STRONG&gt; command for eligible traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can somebody explain what does this refer to ?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:02:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807320#M491109</guid>
      <dc:creator>Siju S</dc:creator>
      <dc:date>2019-03-11T22:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM idle connection timeout issues</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807321#M491112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kausar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is correct (this will affect only protocols that use secondary flow channels) for secondary flows just like the ones used by FTP Data flows or&amp;nbsp; SQL*Net got to be limited with the timeout conn , so if you you try to restrict it with the set connection timeout this with not affect that traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The thing is that as soon as you apply the timeout conn this will affect all the traffic traversing the ASA so you got to be careful on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps, if not let me know and I would try to get more info for you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Dec 2011 04:51:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807321#M491112</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-15T04:51:25Z</dc:date>
    </item>
    <item>
      <title>FWSM idle connection timeout issues</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807322#M491114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your speedy reply , it sounds true . Ive got to be careful enough to set the timout to unlimited for all flows but i dont have another way infact.coz the real issue seems that all my applications are oracle/sqlnet connections looses connection after the default set 60 min period. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However could you tell me what would be the impact if the conn count shows a lot of idle sessions ..ie if the global is set to never timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at present it shoes :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7649 in use, 37873 most used&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Dec 2011 05:33:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807322#M491114</guid>
      <dc:creator>Siju S</dc:creator>
      <dc:date>2011-12-15T05:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM idle connection timeout issues</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807323#M491115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kausar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sure, the resut will affect the performance of the ASAl, I mean remember that each ASA plataform has a limit of connection that the device can handle by minute. So if it gets oversubscrided you will start seeing packets drops, latency issues, high cpu, etc, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, if the global is set to never time out that will means that the connections will never expire so the ASA will have them always on its connection table with will cause some issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had worked with a customer and what he had or his issue was that sometimes the ASA will start dropping some of its tcp connections, and this happened randomly. Once I got access to the ASA first time I check was the global time-out, nothing there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I went to the MPF configuration and there was the issue tcp timeout 0 0 witch cause the ASA to keep all the connections&amp;nbsp; on the ASA, they will never time out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Dec 2011 05:58:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807323#M491115</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-15T05:58:38Z</dc:date>
    </item>
    <item>
      <title>FWSM idle connection timeout issues</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807324#M491116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Appreciate your references, what could be the best bet yet , because i cannot single out the Sql*net traffic and set the timeout to never. The reason beiong i cannot change the session behavior of the applications.&lt;/P&gt;&lt;P&gt;Do you think I should set the global to 'never' and create a broader service policy rule to set the default timeout(1hr) for an identified chunk of traffic from a known direction (eg ; from outside to all protected zones )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Dec 2011 06:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807324#M491116</guid>
      <dc:creator>Siju S</dc:creator>
      <dc:date>2011-12-15T06:04:23Z</dc:date>
    </item>
    <item>
      <title>FWSM idle connection timeout issues</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807325#M491117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello kausar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is a valid option but you will need to do something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-list Conn_rule deny tcp any any eq 150 &lt;/P&gt;&lt;P&gt;Access-list Conn_rule permit tcp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map test&lt;/P&gt;&lt;P&gt;match access-list Conn_rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Policy-map Global_policy&lt;/P&gt;&lt;P&gt;class test&lt;/P&gt;&lt;P&gt;set connection timeout tcp xx:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then create the global timeout for the SQL*Net traffic&lt;/P&gt;&lt;P&gt;timeout conn xx:xx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would not recommend to use the 0 0 but we can give it a try and see if that solves your problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Dec 2011 06:55:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807325#M491117</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-15T06:55:53Z</dc:date>
    </item>
    <item>
      <title>FWSM idle connection timeout issues</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807326#M491118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah will try that , need to change the &lt;/P&gt;&lt;P&gt;Global_policy which presently is set to Class-map: inspection_default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Global policy:&lt;/P&gt;&lt;P&gt;&amp;nbsp; Service-policy: global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dns maximum-length 512, packet 12057789, drop 404, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 268865, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 h225, packet 96244, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 ras, packet 388, drop 388, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: netbios, packet 13248279, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rsh, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: skinny, packet 93279084, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sunrpc, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: tftp, packet 12369199, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sip, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: xdmcp, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Dec 2011 08:13:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807326#M491118</guid>
      <dc:creator>Siju S</dc:creator>
      <dc:date>2011-12-15T08:13:56Z</dc:date>
    </item>
    <item>
      <title>FWSM idle connection timeout issues</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807327#M491119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kausar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know as soon as you get the result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a great day,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Dec 2011 17:18:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807327#M491119</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-15T17:18:22Z</dc:date>
    </item>
    <item>
      <title>FWSM idle connection timeout issues</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807328#M491120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That seems to be it the database connectivity seems to be matching the global policy now , well I did not make it unlimited for the global_policy however limited it to 6hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know whether you have a standarad list of connections categorised as secondary flows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your help .you have a great day &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Dec 2011 15:12:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807328#M491120</guid>
      <dc:creator>Siju S</dc:creator>
      <dc:date>2011-12-19T15:12:31Z</dc:date>
    </item>
    <item>
      <title>FWSM idle connection timeout issues</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807329#M491121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kausar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great to hear that now that you have changed is working as you want it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will do some research and will keep you posted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Dec 2011 20:25:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/1807329#M491121</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-19T20:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM idle connection timeout issues</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/3767792#M491122</link>
      <description />
      <pubDate>Fri, 21 Dec 2018 09:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/3767792#M491122</guid>
      <dc:creator>ravispillay</dc:creator>
      <dc:date>2018-12-21T09:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM idle connection timeout issues</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/3767794#M491123</link>
      <description>&lt;P&gt;I'm having this same issue with Oracle connection. The error code is ORA-12571 TNS Write Failure. When I connect for the first time it times out. When I reconnect to Oracle about three times then the connection is established. I have asked by our DB admin to check the firewall configurations for session timeouts for Oracle listen port 1526 which seems to be timing out. Any help will be appreciated. Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2018 10:02:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idle-connection-timeout-issues/m-p/3767794#M491123</guid>
      <dc:creator>ravispillay</dc:creator>
      <dc:date>2018-12-21T10:02:31Z</dc:date>
    </item>
  </channel>
</rss>

