<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA vs PIX timeout in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-vs-pix-timeout/m-p/1774529#M533951</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please upload the file using "advanced editor" on top right. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Aug 2011 15:40:08 GMT</pubDate>
    <dc:creator>csaxena</dc:creator>
    <dc:date>2011-08-09T15:40:08Z</dc:date>
    <item>
      <title>ASA vs PIX timeout</title>
      <link>https://community.cisco.com/t5/network-security/asa-vs-pix-timeout/m-p/1774526#M533942</link>
      <description>&lt;P&gt;A few weeks ago, I replaced a PIX 515E with a pair of ASA 5520's.&amp;nbsp;&amp;nbsp;&amp;nbsp; We have a few basic web applications behind the ASA's.&amp;nbsp;&amp;nbsp; Nothing complex;&amp;nbsp; just port 80/443 traffic.&amp;nbsp;&amp;nbsp;&amp;nbsp; During the swap, we basically just copied the config from the PIX to the ASA.&amp;nbsp;&amp;nbsp; So the config is virtually identical.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the swap, we have one small set of users who gets timed out when trying to get to the application.&amp;nbsp;&amp;nbsp;&amp;nbsp; This small set of users are scattered across the state of Alaska, and they are all accessing the Internet via a satellite connection.&amp;nbsp;&amp;nbsp; All other users across North America can access the application just fine.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the satellite connections are relatively slow, but they worked fine when going through the PIX, I suspect the issue is a difference in the default TTL (or similar parameter) between the PIX and the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know what this paramter would be.&amp;nbsp; I've been scratching my head for days on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vs-pix-timeout/m-p/1774526#M533942</guid>
      <dc:creator>david_opalenik</dc:creator>
      <dc:date>2019-03-11T21:09:21Z</dc:date>
    </item>
    <item>
      <title>ASA vs PIX timeout</title>
      <link>https://community.cisco.com/t5/network-security/asa-vs-pix-timeout/m-p/1774527#M533945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share the outputs of "show run timeout" and "sho conn details" and what version of ASA are you using ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Chirag&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Aug 2011 15:28:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vs-pix-timeout/m-p/1774527#M533945</guid>
      <dc:creator>csaxena</dc:creator>
      <dc:date>2011-08-09T15:28:01Z</dc:date>
    </item>
    <item>
      <title>ASA vs PIX timeout</title>
      <link>https://community.cisco.com/t5/network-security/asa-vs-pix-timeout/m-p/1774528#M533949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 8.0(4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SPRO-ASA# show runn timeout&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The output of "sho conn detail" is many pages long.&amp;nbsp;&amp;nbsp; Should I filter output on &lt;/P&gt;&lt;P&gt;something to make it more helpful?&amp;nbsp;&amp;nbsp; What specifically should I look for in the &lt;/P&gt;&lt;P&gt;output of "show conn detail"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Aug 2011 15:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vs-pix-timeout/m-p/1774528#M533949</guid>
      <dc:creator>david_opalenik</dc:creator>
      <dc:date>2011-08-09T15:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA vs PIX timeout</title>
      <link>https://community.cisco.com/t5/network-security/asa-vs-pix-timeout/m-p/1774529#M533951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please upload the file using "advanced editor" on top right. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Aug 2011 15:40:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vs-pix-timeout/m-p/1774529#M533951</guid>
      <dc:creator>csaxena</dc:creator>
      <dc:date>2011-08-09T15:40:08Z</dc:date>
    </item>
    <item>
      <title>ASA vs PIX timeout</title>
      <link>https://community.cisco.com/t5/network-security/asa-vs-pix-timeout/m-p/1774530#M533953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Output of "show conn detail" was uploaded.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Aug 2011 15:50:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vs-pix-timeout/m-p/1774530#M533953</guid>
      <dc:creator>david_opalenik</dc:creator>
      <dc:date>2011-08-09T15:50:46Z</dc:date>
    </item>
    <item>
      <title>ASA vs PIX timeout</title>
      <link>https://community.cisco.com/t5/network-security/asa-vs-pix-timeout/m-p/1774531#M533956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a set of IP addresses facing this issue? You could try increasing the idle timeout for TCP connections using the &lt;STRONG&gt;timeout conn&lt;/STRONG&gt; command though i find it highly improbably that the connections fomr the Alaska users is idle for 1 hour.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How long does the connection work before they start timing out?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Aug 2011 18:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vs-pix-timeout/m-p/1774531#M533956</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2011-08-23T18:59:55Z</dc:date>
    </item>
  </channel>
</rss>

