01-31-2019 06:16 AM
Hi
we have a WSA (Explicit mode) and long term https session (without decryption) between a client and a server.
We observed that after 24hours (and one time after 25hours) the WSA send TCP FIN ACK to the client and the server.
This kills the session on both ends.
But we have data in the connection all the time.
Do you know why the WSA kills the active session after 24 respectively 25 hours?
Br Matthias
01-31-2019 08:22 AM
What is the version of code, is this virtual or appliance ?
01-31-2019 08:27 AM
Its a appliance S380 with code 10.5.x
02-10-2019 01:29 AM
check which side is initiating the termination with a "FIN" message, in response to which you see a FIN ACK, a packet capture would help and the exact Version and build.
02-11-2019 01:16 AM
In the capture we see that WSA is sending the initial FIN ACK to both sides.
(i check it with my PC and see that session close starts really with FIN ACK)
Name: S380
Product: Cisco S380 Web Security Appliance
Model: S380
Version: 10.5.3-025
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide