<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX timeout conn recommendations in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-timeout-conn-recommendations/m-p/298714#M610443</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Art,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not a problem.  I am not exactly sure what you mean by the question.  The conn timer is the time that the PIX will allow the connection to sit idle before tearing it down.  If we see traffic flow across this connection, the timer resets to 0.  If we reach the configured time and the timer has not been reset, the connection gets torn down.  Does this answer your question at all?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Dec 2003 21:04:20 GMT</pubDate>
    <dc:creator>scoclayton</dc:creator>
    <dc:date>2003-12-09T21:04:20Z</dc:date>
    <item>
      <title>PIX timeout conn recommendations</title>
      <link>https://community.cisco.com/t5/network-security/pix-timeout-conn-recommendations/m-p/298711#M610440</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are the possible performance problems and security issues with increasing the timeout values (conn especially)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any recommendations as to the max values?  I cannot find anything other than syntax on the web site.  &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:08:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-timeout-conn-recommendations/m-p/298711#M610440</guid>
      <dc:creator>aemr</dc:creator>
      <dc:date>2020-02-21T07:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: PIX timeout conn recommendations</title>
      <link>https://community.cisco.com/t5/network-security/pix-timeout-conn-recommendations/m-p/298712#M610441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The defualt values are the recommended values under normal circumstances but we do realize that there are some situations where these values will not work.  From a Security standpoint and performance standpoint, you probably will not see any change when bumping the conn timeout upa bit.  The only real difference is that the PIX will wait longer before tearing down connections that have gone idle.  You *could* see more conns stored which will eat more memory but in most cases, this will probably be negligable.  Most PIX installations have very few conns that time out due to the idle timer being reached unless there is some application that passes across the PIX that is left open and un-used for long periods of time.  Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2003 20:04:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-timeout-conn-recommendations/m-p/298712#M610441</guid>
      <dc:creator>scoclayton</dc:creator>
      <dc:date>2003-12-09T20:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: PIX timeout conn recommendations</title>
      <link>https://community.cisco.com/t5/network-security/pix-timeout-conn-recommendations/m-p/298713#M610442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Last Q...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the relationship between the connection and idle timeouts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Art&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2003 20:47:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-timeout-conn-recommendations/m-p/298713#M610442</guid>
      <dc:creator>aemr</dc:creator>
      <dc:date>2003-12-09T20:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: PIX timeout conn recommendations</title>
      <link>https://community.cisco.com/t5/network-security/pix-timeout-conn-recommendations/m-p/298714#M610443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Art,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not a problem.  I am not exactly sure what you mean by the question.  The conn timer is the time that the PIX will allow the connection to sit idle before tearing it down.  If we see traffic flow across this connection, the timer resets to 0.  If we reach the configured time and the timer has not been reset, the connection gets torn down.  Does this answer your question at all?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2003 21:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-timeout-conn-recommendations/m-p/298714#M610443</guid>
      <dc:creator>scoclayton</dc:creator>
      <dc:date>2003-12-09T21:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: PIX timeout conn recommendations</title>
      <link>https://community.cisco.com/t5/network-security/pix-timeout-conn-recommendations/m-p/298715#M610444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We bumped our xlate value up to 6 hours.  Then I dump the xlate table every 6 hours using a TCL/expect script. Then I correlate my DHCP logs with the xlate entries.  Purpose being to track a user down by the global IP address they were surfing with.  Anybody have any comments about the accuracy of doing this?  The concept to use this info for enforcement purposes. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2003 21:35:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-timeout-conn-recommendations/m-p/298715#M610444</guid>
      <dc:creator>dlac455</dc:creator>
      <dc:date>2003-12-09T21:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: PIX timeout conn recommendations</title>
      <link>https://community.cisco.com/t5/network-security/pix-timeout-conn-recommendations/m-p/298716#M610445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes that does Scott.  Sorry about the poor wording.  I appreciate the help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Art&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2003 21:41:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-timeout-conn-recommendations/m-p/298716#M610445</guid>
      <dc:creator>aemr</dc:creator>
      <dc:date>2003-12-09T21:41:47Z</dc:date>
    </item>
  </channel>
</rss>

