07-11-2019 02:26 AM
Hi everyone,
I just got in a strange situation here. I've got an ASA 5516-x with Software Version 9.9(2)36.
We have some services which are connecting from DMZ site to LAN site via 1521 (sqlnet) to an oracle database. Sometimes when there is no traffic session is just being disconnected, however when you roll in the same service in LAN segment only it stays connected.
My question is, does ASA have some policy to disconnect idle sessions and clear the session table and if yes, is there a possibility to tweak that for the longer time or exclude this specific traffic at all?
Thank you in advance!
Solved! Go to Solution.
07-11-2019 09:40 AM
Yes, the ASA has connection idle timeouts for different protocols. You can change this as well:
Default timeout for TCP is 1 hour.
07-11-2019 09:40 AM
Yes, the ASA has connection idle timeouts for different protocols. You can change this as well:
Default timeout for TCP is 1 hour.
07-13-2019 10:49 PM
Hello, Rahul.
Really appreciate the help. I created a class map, which applied to policy map and applied to LAN interface with unlimited conn and unlimited half-close for sqlnet traffic for ingress traffic for that specific service. Seems working like a charm.
Regards,
Olim
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide