cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
428
Views
5
Helpful
2
Replies
Highlighted

Timeout issue on ASA connections

I have a weird issue that I think I've narrowed down to being related to the timing out of connections inside my DMZ.

I was wondering first, are there any issues I should keep in mind when I start increasing the stock timeout values for conections?

Say if I double them, other than increased memory usage on my ASA, any other concerns?

Also, can anyone spot any value here that don't look default? It's from a Cisco ASA 55XX. I don't have another to compare it to.

My initial guess is my issue might be the 'half-closed' value, but I'm not sure yet.

arp timeout 14400

timeout xlate 3:00:00

timeout conn 1:00:00

half-closed 0:10:00

udp 0:02:00

icmp 0:00:02

timeout sunrpc 0:10:00

h323 0:05:00

h225 1:00:00

mgcp 0:05:00

mgcp-pat 0:05:00

timeout sip 0:30:00

sip_media 0:02:00

sip-invite 0:03:00

sip-disconnect 0:02:00

timeout sip-provisional-media 0:02:00

uauth 0:05:00 absolute

timeout tcp-proxy-reassembly 0:01:00

Thanks in advance,

Jon

Everyone's tags (2)
2 REPLIES 2
Highlighted
Contributor

Timeout issue on ASA connections

The default timeout are in this document but look's like it's all default.

You need to monitor the numbre of active connection and insure you dont max you appliance.

http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/t.html#wp1540870

Highlighted

Timeout issue on ASA connections

Good stuff. Thanks!

CreatePlease to create content
Content for Community-Ad