01-04-2005 07:14 AM - edited 03-09-2019 09:54 AM
I need help interpreting the below. Xlate timeouts on this PIX are set for 3 hours. Host 192.168.5.4 is showing IDLE status with a 7 hour 35 minute xlate time. Shouldn't the PIX have timed the translation out after 3 hours, or am I reading this incorrectly? Thanks,
PIX1# sh xlate debug | grep 192.168.5.4
NAT from inside:192.168.5.4 to vBNS:192.168.5.4 flags s idle 7:35:00 timeout 3:00
:00
NAT from inside:192.168.5.4 to IDN:192.168.5.4 flags s idle 0:57:25 timeout 3:00:
00
PIX1# sh timeout
timeout xlate 3:00:00
timeout conn 2:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
01-05-2005 08:10 AM
You are reading this correctly. What version of code are you running on this PIX?
Scott
01-05-2005 03:17 PM
6.3(3)
01-06-2005 08:02 AM
As far as I understand "flags s" means that translation is static, and again to my understanding static translations are not going to expire from XLATE. FOr example, here's what I found inside my PIX:
NAT from inside:10.25.4.82 to dmz:10.25.4.82 flags s idle 325:30:04 timeout 3:00:00
Hope this would help.
Alex.
01-06-2005 10:10 AM
OK, that helps. thanks!
01-06-2005 04:06 PM
Ooops, missed the static flag in the orginal post. Thanks for catching that and you are correct.
Scott
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide