<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic H.323 Calls disconnecting by TCP idle timeout in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/h-323-calls-disconnecting-by-tcp-idle-timeout/m-p/1869626#M492721</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How often do the endpoints send keepalive packets across the TCP/1720 control channel? If the keepalives aren't sent at least once an hour, the idle timeout will kick in and tear down the control channel. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You'll just need to determine the interval of the keepalives and adjust the timeout accordingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Nov 2011 21:07:23 GMT</pubDate>
    <dc:creator>mirober2</dc:creator>
    <dc:date>2011-11-22T21:07:23Z</dc:date>
    <item>
      <title>H.323 Calls disconnecting by TCP idle timeout</title>
      <link>https://community.cisco.com/t5/network-security/h-323-calls-disconnecting-by-tcp-idle-timeout/m-p/1869625#M492719</link>
      <description>&lt;P&gt;We are running "ip inspect" on a 3941 router with IOS version15.2(1)T1. We enabled inspection for H.323 :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect name iosfw h323&lt;/P&gt;&lt;P&gt;ip inspect name iosfw h323-nxg&lt;/P&gt;&lt;P&gt;ip inspect name iosfw h323-annexe&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using the default TCP idle-timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3945-Router#sh ip inspect config | in tcp&lt;/P&gt;&lt;P&gt;max-incomplete tcp connections per host is 50. Block-time 2 minutes.&lt;/P&gt;&lt;P&gt;tcp synwait-time is 30 sec -- tcp finwait-time is 5 sec&lt;/P&gt;&lt;P&gt;tcp idle-time is 3600 sec -- udp idle-time is 120 sec&lt;/P&gt;&lt;P&gt;tcp reassembly queue length 16; timeout 5 sec; memory-limit 1024 kilo bytes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; tcp alert is on audit-trail is off timeout 3600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After we establish a H.323 call I can see that the inspection process starts the idle timmer on port 1720/TCP and the call is disconnected after an hour with the following log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%FW-6-DROP_PKT: Dropping h323 session x.x.x.x:17174 y.y.y.y:1720&amp;nbsp; due to&amp;nbsp; Segment matching no TCP connection with ip ident 7154 tcpflags 0x5004 seq.no 3486961044 ack 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the sessios incrementing the Last Heard timer:&lt;/P&gt;&lt;P&gt;Session 1C1FB8C (x.x.x.x:17168)=&amp;gt;(y.y.y.y:1720) h323 SIS_OPEN&lt;/P&gt;&lt;P&gt; Created 00:04:07, Last heard 00:04:07&lt;/P&gt;&lt;P&gt; Bytes sent (initiator:responder) [255:323]&lt;/P&gt;&lt;P&gt; Out SID y.y.y.y[1720:1720]=&amp;gt;x.x.x.x[17168:17168] on ACL outbound&lt;/P&gt;&lt;P&gt; In&amp;nbsp; SID y.y.y.y[1720:1720]=&amp;gt;x.x.x.x[17168:17168] on ACL inbound&amp;nbsp; (9 matches)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I played around with the H323 timeout and the TCP idle-timout , this is how I found that the default TCP idle-timeout was causing the disconnect. If I set that timmer to 5min the call disconnects in 5 minutes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone come across this problem and be willing to share how they have addressed it. I am continuing to troubleshoot the problem but thought I would post it out there to ask.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;--MG&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:53:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h-323-calls-disconnecting-by-tcp-idle-timeout/m-p/1869625#M492719</guid>
      <dc:creator>mikegatti</dc:creator>
      <dc:date>2019-03-11T21:53:38Z</dc:date>
    </item>
    <item>
      <title>H.323 Calls disconnecting by TCP idle timeout</title>
      <link>https://community.cisco.com/t5/network-security/h-323-calls-disconnecting-by-tcp-idle-timeout/m-p/1869626#M492721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How often do the endpoints send keepalive packets across the TCP/1720 control channel? If the keepalives aren't sent at least once an hour, the idle timeout will kick in and tear down the control channel. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You'll just need to determine the interval of the keepalives and adjust the timeout accordingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Nov 2011 21:07:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/h-323-calls-disconnecting-by-tcp-idle-timeout/m-p/1869626#M492721</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-11-22T21:07:23Z</dc:date>
    </item>
  </channel>
</rss>

