<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Change the IDLE timeout for a specific host in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/change-the-idle-timeout-for-a-specific-host/m-p/1638114#M594964</link>
    <description>&lt;P&gt;Platform: FWSM 3.2(18)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to change the idle connection timeout for a specific host. I'm pretty sure the following policy will achieve this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;begin code extract&amp;gt;&lt;/P&gt;&lt;P&gt;access-list CMS-TIMEOUT permit tcp any host 10.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map CMS-TIMEOUT&lt;/P&gt;&lt;P&gt; match access-list CMS-TIMEOUT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map CMS-TIMEOUT&lt;BR /&gt; class CMS-TIMEOUT&lt;BR /&gt; set connection timeout idle 4:0:0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy conns interface outside&lt;/P&gt;&lt;P&gt;&amp;lt;end code extract&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is, will the above policy override the global policy configuration applied to the outside interface. We only have the std default glovbal policy applied i.e. no other service policies are used?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 19:31:43 GMT</pubDate>
    <dc:creator>axa_tech_uk</dc:creator>
    <dc:date>2019-03-11T19:31:43Z</dc:date>
    <item>
      <title>Change the IDLE timeout for a specific host</title>
      <link>https://community.cisco.com/t5/network-security/change-the-idle-timeout-for-a-specific-host/m-p/1638114#M594964</link>
      <description>&lt;P&gt;Platform: FWSM 3.2(18)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to change the idle connection timeout for a specific host. I'm pretty sure the following policy will achieve this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;begin code extract&amp;gt;&lt;/P&gt;&lt;P&gt;access-list CMS-TIMEOUT permit tcp any host 10.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map CMS-TIMEOUT&lt;/P&gt;&lt;P&gt; match access-list CMS-TIMEOUT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map CMS-TIMEOUT&lt;BR /&gt; class CMS-TIMEOUT&lt;BR /&gt; set connection timeout idle 4:0:0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy conns interface outside&lt;/P&gt;&lt;P&gt;&amp;lt;end code extract&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is, will the above policy override the global policy configuration applied to the outside interface. We only have the std default glovbal policy applied i.e. no other service policies are used?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:31:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-the-idle-timeout-for-a-specific-host/m-p/1638114#M594964</guid>
      <dc:creator>axa_tech_uk</dc:creator>
      <dc:date>2019-03-11T19:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: Change the IDLE timeout for a specific host</title>
      <link>https://community.cisco.com/t5/network-security/change-the-idle-timeout-for-a-specific-host/m-p/1638115#M594968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Long story short, your policy on interface takes precedence over global as it will be the first one to be hit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm40/configuration/guide/mpf_f.html#wp1137086"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm40/configuration/guide/mpf_f.html#wp1137086&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I might be wrong, but that's the way I recollect it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 14:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-the-idle-timeout-for-a-specific-host/m-p/1638115#M594968</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2011-01-07T14:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Change the IDLE timeout for a specific host</title>
      <link>https://community.cisco.com/t5/network-security/change-the-idle-timeout-for-a-specific-host/m-p/1638116#M594973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply, what I really mean, is will it be the only policy appilled i.e. will the global policy no longer be applied, or does the global policy always get applied and will always be processed. Assuming it is appllied globally?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 14:38:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-the-idle-timeout-for-a-specific-host/m-p/1638116#M594973</guid>
      <dc:creator>axa_tech_uk</dc:creator>
      <dc:date>2011-01-07T14:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: Change the IDLE timeout for a specific host</title>
      <link>https://community.cisco.com/t5/network-security/change-the-idle-timeout-for-a-specific-host/m-p/1638117#M594977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The global policy will be applied after the interface specific policy - which does take precedence.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jan 2011 15:59:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-the-idle-timeout-for-a-specific-host/m-p/1638117#M594977</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2011-01-07T15:59:14Z</dc:date>
    </item>
  </channel>
</rss>

