01-26-2015 08:16 AM - edited 03-11-2019 10:24 PM
Hello I upgraded our Cisco ASA 5520 with a Cisco ASA 5585. Though both ASA were configured with default TCP Idle Connection Timeout values people are now starting to complaint that idle SSH connections are being terminated. This is proper behavior but they were claiming it didn't occur with the old firewall. Our users are setting keepalives for 1800 seconds to get around this before I can bump the setting to infinite (setting 0). Is there a bug with the feature in older ASA OS?
01-27-2015 01:36 AM
Hi,
Before looking for a bug I would check the ASA logs (hopefully you are storing them to a separate Syslog server) and see why the connections are torn down (Teardown reason) and how long have they been on the ASAs connection table before they were torn down.
You also have the option to perform traffic capture on the ASA for the traffic in question and confirm why or which party terminates the connection.
I guess you can use the MPF on the ASA to configure separate idle timeouts for just these SSH Connections if you do not want to touch the global timeout values.
I have not run into any problems with the timeout settings on the older softwares. In the newer softwares (8.3+) I have run into these problems. In those situation the ASA has not removed the connection that have reached the timeout value. I have seen connection that have been idle for over 1000h.
- Jouni
11-16-2016 02:43 AM
Hello Jouni Forss,
recently we've got into the similar problem (ASA 9.4 doesnt tear down connections with >1h default and 5m configured for most of connections idle timer. Did u identify the reason why it happened?
Thank u,
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide