cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1440
Views
0
Helpful
7
Replies

HTTP inspection problem

Hi, I have configured IOS Zone Based Firewall on my office 871 router.

I've made an inspection rules for http, https, icmp and dns for in-out zone. Often I can see in router log the message:

%APPFW-3-HTTP_MAX_REQ_EXCEEDED : Number of unanswered HTTP requests exceeded the limit 10.

I guess this is becouse there are about 7 people working simultaneously and some of them use skype, witch probably makes unanswered sessions.

However, i want to ask, is there some way to change the limit of 10 unanswered request?

Thanks in advance!

1 Accepted Solution

Accepted Solutions

The limit is raised to 64 in 12.4(20)T.You can give a try with that.

View solution in original post

7 Replies 7

ivillegas
Level 6
Level 6

This error message means firewall sees 10 outstanding requests without any reply over a single TCP connection. Normally this shouldn't happen unless you have huge delay in the network or the HTTP server is very slow in responding to the request.

Thanks for reply!

I understand what the error message means, but I don't know how to prevent it.

I'm sure that it's NOT from the network delay or internet connection speed (ADSL - 12Mb/s).

I need to increase the limit number of 10 unopened connections. Is this possible?

Thanks!

sadsiddi
Level 1
Level 1

What version of IOS do you use now?

my version of IOS is 12.4(15)T with Advanced Ip services, and i've configured a Zone-Based-Firewall

The limit is raised to 64 in 12.4(20)T.You can give a try with that.

Thank you very much, I'll try it next week and i hope that will helps me..

Henry Gonzales
Level 1
Level 1

Hi,

I also have the some problem.

I have: c1841-advsecurityk9-mz.124-4.T7.bin - Version 12.4(4)T7

ROM: System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1)

I have to upgrade IOS?

Thanks in advance!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card