cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1301
Views
0
Helpful
15
Replies

Telnet thru pix520 to AIX host disconnects when idle

annmarie.harper
Level 1
Level 1

I have a PIX 520 running ios 6.2.4. We have this doing a site to site tunnel - tunnel is not going down , but the complaints that I am getting is that if a user is idle for more than 1 hour they are getting disconnect from their application server which is the AIX. Now I have already change the time-out connection from 1 hour to be 8, I have also changed the half-closed to be 8 hours also. I have saved the config once the changes were made yet I am still getting the disconnects . Any ideas ????

15 Replies 15

ciscokrishna
Level 1
Level 1

you might as well check the aplication end on the AIX server. It might be having a idle timeout.

I have checked that first . They actually use a telnet session using procom to get to the unix box I have also checked the software to see if there was any thing there that was causing this.

They use to be connected ADSL to a hub site and frame to their host when it was set up that way there was no issue.

They can be idle for hours and hours without the disconnect .

Now the only thing I did not do was reboot the f/wall , I did save the config though. U dont think that I need to reboot the darn thing do u.

I have also discovered something else . When the users are being disconnected the f/wall still shows the connections as up and being idle for some period . Again any ideas.

Allo Ann-Marie,

1) Is there a third party involved in the telnet session? If the answer is yes, you should check what is the amount of idle-timeout set on that device. The pix must have a longer idle-timeout than all other devices.

2) You may also put a sniffer to check a connection-FIN flag from the hosts. This will prove the PIX isn't in error but comes from the application running on the device.

Michel

mpalardy
Level 3
Level 3

Sorry, forget my last reply. I've re-read your problem description and noticed you were using a tunnel. Ok when you do a show isakmp sa and show ipsec sa, do you get any error on the tunnel itself?

ciscokrishna
Level 1
Level 1

Hey,

I don't think this is a problem with the tunnel. Any ways, u check the logs for the tunnel issues, but u'll find only the renegotiation (if happening) or translation logs. In your post, u said something like u used a ADSL connection to HUB site and then to server and no issues were there in that. This shows that it might be a problem of connectivity from the client end. I don't think PIX has gotta do anything in this. Anyways, it would be helpful if u check the logs and the application end. By the way, what are u using to telnet?? putty or tera term??

Appreciate your comments.

They use Procomm 4.8 which I also have on my laptop and I have gone thru everything to see if there is an idle timeout or anything like that on procomm and there isnt. And when they were on their private network they did not get disconnected when they were idle . This only started when we took over their network.

ebeekman
Level 1
Level 1

Are all the users disconnected at the same time? Or is each user disconnected on a different time.

If they all are disconnected at the same time, it could be a vpn timer issue. You can see this when you turn on vpn debugging.

Otherwise it could be a connection issue from the client to the AIX.

Edwin

No it is only users that are away for over 1 hour.

dpatel
Level 1
Level 1

I have same problem. Spent weeks and no solution from Cisco also.

ok.. to check if this is really a VPN issue, the client can do a ping with "-t" option (in wondows) and go away from comp. you can even use a redirection pipe (>) to send it to a file ( i understand it eats up HDD, but ok for testing). after sometime check the file. if there is a continuous "no response" for more than 10-15 pings... u can doubt the vpn.

I have the same problem but it is a firewall, not a VPN issue. We moved a site that worked fine off a T-1 to a gig fiber connection coming through a FWSM and we started getting these errors on emulator connections to AIX box. Three emulators later and the same error occurs. I have changed the timeouts on the FWSM PIX but no luck. I hope this thread is kept up. I could use some help on this one also.

I was thinking about NAT time out is issue.But thant is not a case.Is anyone has Case with TAC and might have some soutions. Becase I used not only third party applications but use putty to keep going null packes all times and same issue.

No luck on other website too.

I have a similar situation. Using a PIX 501 with a VPN tunnel to a Watchguard Firebox 1000. PCs are using AccuTerm but I have also used Hyperterm and Eterm with same result. Here is what I have found so far. I also have Wyse terminals connected through terminal servers which do not lose connectivity. PCs only lose connection if there is no activity on the connection to the AIX. The problem only started when I introduced the PIX/VPN connection and happens at all 5 of my sites now. If I set the terminal emulator to access the AIX directly, i.e. use NAT/PAT on the Firebox with a telnet port to the IBM, the problem is resolved, however this little security breach fix is unnacceptable. I also have 2 sites that do not have PIX units which do not have this problem.