cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1331
Views
0
Helpful
4
Replies

WSA session end

wess
Level 1
Level 1

Hi

 

we have a WSA (Explicit mode) and long term https session (without decryption) between a client and a server.

We observed that after 24hours (and one time after 25hours) the WSA send TCP FIN ACK to the client and the server.

This kills the session on both ends.

But we have data in the connection all the time.

 

Do you know why the WSA kills the active session after 24 respectively 25 hours?

 

Br Matthias 

 

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

What is the version of code, is this virtual or appliance ?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Its a appliance S380 with code 10.5.x

Lokesh Kumar Lal
Cisco Employee
Cisco Employee

check which side is initiating the termination with a "FIN" message, in response to which you see a FIN ACK, a packet capture would help and the exact Version and build.

Regards,
Lokesh K. Lal
Engineering Product Manager
Cisco Systems Inc.

Please don't forget to rate useful posts

In the capture we see that WSA is sending the initial FIN ACK to both sides.

(i check it with my PC and see that session close starts really with FIN ACK)

 

Name: S380
Product: Cisco S380 Web Security Appliance
Model: S380
Version: 10.5.3-025

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: