cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1442
Views
0
Helpful
7
Replies

HTTP inspection problem

Hi, I have configured IOS Zone Based Firewall on my office 871 router.

I've made an inspection rules for http, https, icmp and dns for in-out zone. Often I can see in router log the message:

%APPFW-3-HTTP_MAX_REQ_EXCEEDED : Number of unanswered HTTP requests exceeded the limit 10.

I guess this is becouse there are about 7 people working simultaneously and some of them use skype, witch probably makes unanswered sessions.

However, i want to ask, is there some way to change the limit of 10 unanswered request?

Thanks in advance!

1 Accepted Solution

Accepted Solutions

The limit is raised to 64 in 12.4(20)T.You can give a try with that.

View solution in original post

7 Replies 7

ivillegas
Level 6
Level 6

This error message means firewall sees 10 outstanding requests without any reply over a single TCP connection. Normally this shouldn't happen unless you have huge delay in the network or the HTTP server is very slow in responding to the request.

Thanks for reply!

I understand what the error message means, but I don't know how to prevent it.

I'm sure that it's NOT from the network delay or internet connection speed (ADSL - 12Mb/s).

I need to increase the limit number of 10 unopened connections. Is this possible?

Thanks!

sadsiddi
Level 1
Level 1

What version of IOS do you use now?

my version of IOS is 12.4(15)T with Advanced Ip services, and i've configured a Zone-Based-Firewall

The limit is raised to 64 in 12.4(20)T.You can give a try with that.

Thank you very much, I'll try it next week and i hope that will helps me..

Henry Gonzales
Level 1
Level 1

Hi,

I also have the some problem.

I have: c1841-advsecurityk9-mz.124-4.T7.bin - Version 12.4(4)T7

ROM: System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1)

I have to upgrade IOS?

Thanks in advance!

Review Cisco Networking products for a $25 gift card