cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
310
Views
0
Helpful
2
Replies

Unexpected timeout on connections

erikcpelletier
Level 1
Level 1

I am experiencing a few problems accessing servers after recently updating the PIX 506E config to enable DNS fixup and alias mappings.

When I attempt to connect to the servers using SSH, there is an extended pause before I receive a login prompt. This is usually the case the first time I try to access the server while subsequent requests may be a littley bit faster. I am more puzzled and bothered by the server dropping the connections. Each connection is timing out after only a few minutes. This was never a problem before making the PIX changes.

Any ideas on what may be happening?

2 Replies 2

Not applicable

Though not directly related, this could be an issue with timers.

klogan
Level 1
Level 1

I have been having the same tcp connection timeout problems. It happens with several different PIX and FWSM units with different software versions. We have determined that it is a 90 second idle period that breaks the connection for the end user. The PIX shows the connection to still be established. As long as a connection is not idle for more than 90 seconds, all is well. As far as I know, there are no 90 second timers on the PIX. It is a problem regardless of which side of the firewall the connection is started on. If the firewall is eliminated from the connection path, there is no problem, so I know the firewall to be the "cause".