CSS flow timeouts on bypass connections

Answered Question
Apr 25th, 2008

Hi,

We use an acl bypass on a CSS11501 to send client connections on specific ports to a database server behind the CSS.

The customer is reporting timeouts on the connection and I'm trying to find out whether the same flow timeouts used on content rules apply for connections that use a bypass acl entry.

If the same timeouts apply, is it possible to change the timeout value? My understanding is that timeouts can only be changed on a content rule and as we're using a bypass acl we don't have one!

We're using 08.10 software.

I have this problem too.
0 votes
Correct Answer by Gilles Dufour about 8 years 7 months ago

the same timeout applies to all connections going through the CSS.

But you can't change the timeout for traffic not hitting a content rule or a group.

What you can do is disable the flow timeout for a particular tcp port with the command 'flow permanent port1 '

Gilles.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Gilles Dufour Fri, 04/25/2008 - 07:10

the same timeout applies to all connections going through the CSS.

But you can't change the timeout for traffic not hitting a content rule or a group.

What you can do is disable the flow timeout for a particular tcp port with the command 'flow permanent port1 '

Gilles.

Actions

This Discussion