cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
684
Views
0
Helpful
2
Replies

Tcp Connection timeout on ASA for vpn traffic

engineer467
Level 1
Level 1

Hello All

I need an answer please.

I wanted to give tcp conenction timeout as unlimited for some IPs coming through VPN.

So, I created an access-list defining the traffic for which I want this tcp timeout.

Then a class map, policy map, entered set timeout to '0'

Applied it under default service-policy, which is applied as global (by default).

My doubt is should I apply the service policy on the interface or the global will work.

Just a silly doubt

Thanks in advance.

1 Accepted Solution

Accepted Solutions

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

I think it should work just fine if you attach it to the default "policy-map" configuration that you have attached globally on the ASA.

You might want to configure the timeout value as something long rather than setting it as unlimited.

- Jouni

View solution in original post

2 Replies 2

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

I think it should work just fine if you attach it to the default "policy-map" configuration that you have attached globally on the ASA.

You might want to configure the timeout value as something long rather than setting it as unlimited.

- Jouni

Yes Jouni, its attached under the default policy-map. And as you have suggested, I have changed the timeout value to few hours.

Thank You again

Abhishek

Review Cisco Networking for a $25 gift card