ASA5520 VPN dropping RDP connections

Unanswered Question
Oct 15th, 2008
User Badges:

HI,

We have been experiencing issues when RDP to a server via L2L VPN Tunnel or/and via Cisco VPN Client.

The issues started to happen since we upgraded an old PIX515E with an ASA5520.

The users only reported RDP problems, for example, The RDP session will hang for 10 seconds and reconnect, or it will freeze for 5 to 10 seconds at random times. We could not find a pattern for this issue. Sometimes happened twice every hour and sometimes won't happened at all.

After opened multiple TAC cases with Cisco VPN specialist, the issue was still on (they couldn't find anything wrong.

So i decided to start searching for similar issues online.

I found a forum with a person describing the same problem with RDP connection running an ASA.

He described he used to have a PIX and no problems, and since they upgrade to an ASA they start having same issues we have.

The good thing is that he found a solution.


He added the following command to the ASA

Timeout conn 0:0:0 (since the Cisco ASA default is 1:0:0) and this fixed the issue for him.


I've added this command yesterday and looks like the we haven't got any issues since then.


Can someone please explain to me what does this command exactly do?

Why this command will fix the RDP issue?

Why this command has to be changed on the ASA from the default when it is not a problem on a PIX?


Hope you can help me,

Thanks,

Zeek


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 4 (1 ratings)
Loading.
singhsaju Wed, 10/15/2008 - 12:53
User Badges:
  • Silver, 250 points or more

Hi Zeek,


It Specifies the idle time after which a connection closes, between 0:05:0 and 1193:0:0. The default is 1 hour (1:0:0). Use 0 to never time out a connection.


http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/t_72.html#wp1387086


As for the PIX , this command also existed as default value for connection timeout to be 1 hour (same as ASA):

http://www.cisco.com/en/US/docs/security/pix/pix62/command/reference/tz.html#wp1026093



HTH

Saju


Zeek Ferraros Wed, 10/15/2008 - 13:43
User Badges:

I knew the command definition.

What I need to know, is why the ASA timeout default affects rdp connections, when the pix default does not. I've found other people on the internet with the same exact problem.

Also is the 0:0:0 will affect the performance of the ASA in any other way?

snooter Tue, 10/27/2009 - 12:35
User Badges:

Kind of bringing this back from the grave but I'm fighting the same issues. I'm curious, did you end up enabling the "timeout conn 0:0:0" command on your asa? Any performance issues or after effects of that?

Actions

This Discussion