<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM sysopt connection timewait ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-sysopt-connection-timewait/m-p/1555579#M601321</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The issue is that the software tries to re-use the same port for a new connection. The firewall will block that with:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: DE-CH; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; Calibri&amp;quot;: ; mso-bidi-theme-font: minor-bidi; "&gt;%FWSM-6-106028: Deny TCP (Connection marked for Deletion) from x.x.x.x/xx to x.x.x.x/xx flags SYN&amp;nbsp; on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: DE-CH; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-bidi-theme-font: minor-bidi; Calibri&amp;quot;: ; "&gt;And this itself is caused because of the time_wait period which seems to be set to 240 seconds. What I would need is to lower that one to 10-30 seconds. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: DE-CH; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-bidi-theme-font: minor-bidi; Calibri&amp;quot;: ; "&gt;The set connection timeout tcp or idle has a minimum of 5 minutes as per your attached link.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Oct 2010 11:17:39 GMT</pubDate>
    <dc:creator>patoberli</dc:creator>
    <dc:date>2010-10-11T11:17:39Z</dc:date>
    <item>
      <title>FWSM sysopt connection timewait ?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-sysopt-connection-timewait/m-p/1555575#M601317</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the command '&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;SPAN style="font-size: 11pt; font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;sysopt connection timewait' available on the FWSM 3.2? There is something written in the manual: [quote]&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Command Reference, 3.2 -- Whole Book PDF" available on the page you sent me to and go to page 6-86 we see the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;sysopt connection timewait&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Description&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11pt; font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;Forces each TCP connection to linger in a shortened TIME_WAIT state after the final normal TCP close-down sequence&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;[/quote]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But on the other hand it's not listed as an available command in the list of commands...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So is it available? What are the options for configuring it? What is the impact for the network?&lt;/P&gt;&lt;P&gt;Our backupsoftware supplier asked us to lower it to 30 seconds or less.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;pato&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:52:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-sysopt-connection-timewait/m-p/1555575#M601317</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2019-03-11T18:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM sysopt connection timewait ?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-sysopt-connection-timewait/m-p/1555576#M601318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The command "sysopt connection timewait" is a global command that is no longer available on version 3.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure the same feature with MPF with configuring specific traffic that you would like to lower the TCP timewait on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the command reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/command/reference/s1.html#wp2699979"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/command/reference/s1.html#wp2699979&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Oct 2010 09:33:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-sysopt-connection-timewait/m-p/1555576#M601318</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-10-11T09:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM sysopt connection timewait ?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-sysopt-connection-timewait/m-p/1555577#M601319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answer. In that case we can't change it to a time that the manufactor would like to have (around 5-10&lt;/P&gt;&lt;P&gt;seconds).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Oct 2010 10:57:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-sysopt-connection-timewait/m-p/1555577#M601319</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2010-10-11T10:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM sysopt connection timewait ?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-sysopt-connection-timewait/m-p/1555578#M601320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On FWSM architecture, the connection is actually removed as soon as they are closed, hence the "sysopt connection timewait" actually serves no purpose, hence it is no longer available in the later version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is your software vendor actually trying to achieve? Do they want to close down the connection around 5-10 seconds after the TCP session is idle? If that is what they are trying to achieve, then you can implement it using the "set connection timeout" command advised earlier.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Oct 2010 11:08:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-sysopt-connection-timewait/m-p/1555578#M601320</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-10-11T11:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM sysopt connection timewait ?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-sysopt-connection-timewait/m-p/1555579#M601321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The issue is that the software tries to re-use the same port for a new connection. The firewall will block that with:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: DE-CH; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; Calibri&amp;quot;: ; mso-bidi-theme-font: minor-bidi; "&gt;%FWSM-6-106028: Deny TCP (Connection marked for Deletion) from x.x.x.x/xx to x.x.x.x/xx flags SYN&amp;nbsp; on interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: DE-CH; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-bidi-theme-font: minor-bidi; Calibri&amp;quot;: ; "&gt;And this itself is caused because of the time_wait period which seems to be set to 240 seconds. What I would need is to lower that one to 10-30 seconds. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; mso-bidi-font-family: 'Times New Roman'; sans-serif&amp;quot;: ; mso-ascii-theme-font: minor-latin; ,&amp;quot;: ; color: #000000; font-size: 11pt; mso-hansi-theme-font: minor-latin; mso-ansi-language: DE-CH; font-family: &amp;quot; mso-fareast-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-bidi-theme-font: minor-bidi; Calibri&amp;quot;: ; "&gt;The set connection timeout tcp or idle has a minimum of 5 minutes as per your attached link.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Oct 2010 11:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-sysopt-connection-timewait/m-p/1555579#M601321</guid>
      <dc:creator>patoberli</dc:creator>
      <dc:date>2010-10-11T11:17:39Z</dc:date>
    </item>
  </channel>
</rss>

