cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
13543
Views
0
Helpful
5
Replies

What is the default idle TCP session time out in FWSM

Ganesh Hariharan
VIP Alumni
VIP Alumni

Hi All,

I would like to know what is the default TCP idle session time out in FWSM and if i want to increase this timer what can be impact and security reasons and how can i do also ? and is there any setting in firewall to increase a idle timeout setting for specific port.

Ganesh.H

1 Accepted Solution
5 Replies 5

Jon Marshall
Hall of Fame
Hall of Fame

ganeshh.iyer wrote:

Hi All,

I would like to know what is the default TCP idle session time out in FWSM and if i want to increase this timer what can be impact and security reasons and how can i do also ? and is there any setting in firewall to increase a idle timeout setting for specific port.

Ganesh.H

Ganesh

It should be one hour. You can view the current timeout settings with "sh timeout" or "sh running-config timeout".

Prior to 3.x code the timeout setting was global so if you changed the TCP timeout it affected all tcp connections. However with v3.x code you can now use Modular Policy Framework to set timeouts for specific ports/IP addresses -

FWSM MPF

Jon

Ganesh

It should be one hour. You can view the current timeout settings with "sh timeout" or "sh running-config timeout".

Prior to 3.x code the timeout setting was global so if you changed the TCP timeout it affected all tcp connections. However with v3.x code you can now use Modular Policy Framework to set timeouts for specific ports/IP addresses -

FWSM MPF

Jon

Jon

Yes my query is cleared just can you provide some other document also for port based increasing the idle time out session in firewall.

Ganesh.H



Thanks Jon  !!

Ganesh.H

Jon Marshall
Hall of Fame
Hall of Fame

Ganesh

Has this solved your query ?

Jon

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card