Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Help with STATIC Command

I am trying to prepare myself for the SNPA exam, and am stuck on the static command. I understand the basic IP to IP translation version of the command (static (IF/IF) IP MASK IP MASK), but I am lost when I start seeing numbers at the end of that string. The command syntax confuses me because there are so many options. For example, examples provided to me for allowing outside access to a DMZ-based web-server are written static (dmz,outside) Out_IP Out_mask Dmz_IP Dmz_mask 0 0 ... What are the zeroes??? I know that you can specify embryonic connection limits, but that is just one of those numbers..what's the other?

Thank you!

Hall of Fame Super Blue

Re: Help with STATIC Command


There are 2 zero's at the end

The first is the maximum number of connections

The second is the numebr of embryonic connections allowed

Have a look at this link for more detail

One other thing. The format of the static command is

static (if/if) IP IP MASK

rather than

static (if/if) IP MASK IP MASK




Re: Help with STATIC Command

the second number - max embryonic connections - allows x amount of embryonic connections per host. Once the 'x' amount is reached, TCP intercept intervenes and the PIX/ASA starts intercepting TCP requests to make sure the 3 way handshake is completed. if the 3 way handshake is completed (via the PIX/ASA), the connection is allowed to seamless complete back to the inside originating host. the default value of zero, basically means TCP intercept will never be used and limitless embryonic connections will be allowed.

New Member

Re: Help with STATIC Command

Thanks! Jon answered my immediate question, and your follow up helped cement it in my head.