WSA session end

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-31-2019 06:16 AM
Hi
we have a WSA (Explicit mode) and long term https session (without decryption) between a client and a server.
We observed that after 24hours (and one time after 25hours) the WSA send TCP FIN ACK to the client and the server.
This kills the session on both ends.
But we have data in the connection all the time.
Do you know why the WSA kills the active session after 24 respectively 25 hours?
Br Matthias
- Labels:
-
Web Security
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-31-2019 08:22 AM
What is the version of code, is this virtual or appliance ?

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-31-2019 08:27 AM
Its a appliance S380 with code 10.5.x
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-10-2019 01:29 AM
check which side is initiating the termination with a "FIN" message, in response to which you see a FIN ACK, a packet capture would help and the exact Version and build.
Lokesh K. Lal
Engineering Product Manager
Cisco Systems Inc.
Please don't forget to rate useful posts

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-11-2019 01:16 AM
In the capture we see that WSA is sending the initial FIN ACK to both sides.
(i check it with my PC and see that session close starts really with FIN ACK)
Name: S380
Product: Cisco S380 Web Security Appliance
Model: S380
Version: 10.5.3-025
