<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Exec-timeout doesn't seem to work in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/exec-timeout-doesn-t-seem-to-work/m-p/2434656#M921982</link>
    <description>&lt;P&gt;I've been having a devil of a time getting exec-timeout to clear idle vty/ssh sessions. This investigation started when we were rolling out new Catalyst 4507R+E switches with Sup7L-E's under IOS XE&amp;nbsp;03.04.02.SG (what they shipped from the factory with.) Idle SSH sessions on the vty lines were not being cleared, despite the config being:&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;BR /&gt;&amp;nbsp;access-class VTY_ACL in&lt;BR /&gt;&amp;nbsp;exec-timeout 30 0&lt;BR /&gt;&amp;nbsp;logging synchronous&lt;BR /&gt;&amp;nbsp;length 0&lt;BR /&gt;&amp;nbsp;transport input ssh&lt;/P&gt;&lt;P&gt;So I opened a TAC case, and eventually they referred to bug&amp;nbsp;CSCug31122. This wasn't terribly satisfying, as we are not talking about new or revolutionary functionality, and a general distribution release on a mature platform. Clearing an idle session does not require the most sophisticated programmer at Cisco. But this led me to do more tests, and I have yet to find a hardware/IOS combination where this works correctly. So far I have failures for:&lt;/P&gt;&lt;P&gt;4507R+E/Sup7L-E/IOS&amp;nbsp;XE&amp;nbsp;03.04.02.SG, both vty and console lines&lt;/P&gt;&lt;P&gt;3560/12.2(40)SE, vty lines with ssh&lt;/P&gt;&lt;P&gt;3750/12.2(44)SE6, vty lines with both telnet and ssh&lt;/P&gt;&lt;P&gt;3845/12.4(24)T6&lt;/P&gt;&lt;P&gt;This seems more than coincidence. Is there something I am missing, or is this an unusually complicated programming issue?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 13:07:26 GMT</pubDate>
    <dc:creator>gkuzmowycz</dc:creator>
    <dc:date>2020-02-21T13:07:26Z</dc:date>
    <item>
      <title>Exec-timeout doesn't seem to work</title>
      <link>https://community.cisco.com/t5/network-security/exec-timeout-doesn-t-seem-to-work/m-p/2434656#M921982</link>
      <description>&lt;P&gt;I've been having a devil of a time getting exec-timeout to clear idle vty/ssh sessions. This investigation started when we were rolling out new Catalyst 4507R+E switches with Sup7L-E's under IOS XE&amp;nbsp;03.04.02.SG (what they shipped from the factory with.) Idle SSH sessions on the vty lines were not being cleared, despite the config being:&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;BR /&gt;&amp;nbsp;access-class VTY_ACL in&lt;BR /&gt;&amp;nbsp;exec-timeout 30 0&lt;BR /&gt;&amp;nbsp;logging synchronous&lt;BR /&gt;&amp;nbsp;length 0&lt;BR /&gt;&amp;nbsp;transport input ssh&lt;/P&gt;&lt;P&gt;So I opened a TAC case, and eventually they referred to bug&amp;nbsp;CSCug31122. This wasn't terribly satisfying, as we are not talking about new or revolutionary functionality, and a general distribution release on a mature platform. Clearing an idle session does not require the most sophisticated programmer at Cisco. But this led me to do more tests, and I have yet to find a hardware/IOS combination where this works correctly. So far I have failures for:&lt;/P&gt;&lt;P&gt;4507R+E/Sup7L-E/IOS&amp;nbsp;XE&amp;nbsp;03.04.02.SG, both vty and console lines&lt;/P&gt;&lt;P&gt;3560/12.2(40)SE, vty lines with ssh&lt;/P&gt;&lt;P&gt;3750/12.2(44)SE6, vty lines with both telnet and ssh&lt;/P&gt;&lt;P&gt;3845/12.4(24)T6&lt;/P&gt;&lt;P&gt;This seems more than coincidence. Is there something I am missing, or is this an unusually complicated programming issue?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:07:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/exec-timeout-doesn-t-seem-to-work/m-p/2434656#M921982</guid>
      <dc:creator>gkuzmowycz</dc:creator>
      <dc:date>2020-02-21T13:07:26Z</dc:date>
    </item>
  </channel>
</rss>

