05-02-2021 10:57 PM
Hello Experts!
So i have a problem that the server has tcp reset flag. My customer want to know is there any way that the cisco ASA reset the tcp connection?
In my understanding that the asa will reset the connection when the tcp session is idle for 1 hour (am i correct?). Is there any possibility that asa reset the tcp connection?
Fyi tcp port, and ip source/dest is legit and allowed in asa rules.
Solved! Go to Solution.
05-02-2021 11:26 PM
You are correct, default tcp idle timeout is :
sh run | inc timeout timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02
The best way to t-shoot this will be to take pcap on the incoming and outgoing traffic interface to prove if the reset is sent by ASA or from the backend.
Regards,
Chakshu
Hope this helps!
05-02-2021 11:26 PM
You are correct, default tcp idle timeout is :
sh run | inc timeout timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02
The best way to t-shoot this will be to take pcap on the incoming and outgoing traffic interface to prove if the reset is sent by ASA or from the backend.
Regards,
Chakshu
Hope this helps!
05-02-2021 11:34 PM
Hello sir thx for the enlighment,
Unfortunetaly that the pcap just on one server, and there is none on the far-end server.
So what happend when the tcp session is more than 1 hour on asa? Does asa send tcp reset flag to both server?
05-02-2021 11:52 PM
That's the timeout value for connection that asa maintains, read more here:
I was asking to take pcap on the incoming and outgoing interface of ASA and not the servers, read more here:
Regards,
Chakshu
Hope this helps!
05-02-2021 11:56 PM
When the one side TCP reset send, the session closed and the TCP needs to re-established again.
here are default TCP Reset timers :
I have seen some application required TCP session always open, if not application required to restart manually to establish a connection,
in that case, you need to configured TCP state bypass as below :
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide