Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

IP Inspect - increase timeout on TCP Port

I have a 2811 router with IP Inspect enable for Ingress traffic but it is quite generic:

ip inspect name firewall tcp

ip inspect name firewall udp

ip inspect name firewall icmp

ip inspect name firewall dns

int Serial1/1

ip inspect firewall out

Inspection name firewall

tcp alert is on audit-trail is off timeout 3600

udp alert is on audit-trail is off timeout 30

icmp alert is on audit-trail is off timeout 10

dns alert is on audit-trail is off timeout 30

I have an application that connects outbound that keeps timing out. It uses a specific TCP port. I'd like to increase this TCP port's timeout period, but keep the other TCP ports at the default.

Is this possible?

Router(config)#ip inspect name firewall tcp ?

alert Turn on/off alert

audit-trail Turn on/off audit trail

router-traffic Enable inspection of sessions to/from the router

timeout Specify the inactivity timeout time

<cr>

2 REPLIES
Silver

Re: IP Inspect - increase timeout on TCP Port

This is the syntax for CBAC.

ip inspect name inspection-name protocol [timeoutseconds]

ip inspect one-minute high

ip inspect max-incomplete high

ip inspect tcp max-incomplete host

New Member

Re: IP Inspect - increase timeout on TCP Port

It looks like I can only do that command for specific protocols though, not for a TCP or UDP port not already defined (like H323), or the entire TCP or UDP port realm.

1037
Views
0
Helpful
2
Replies
CreatePlease to create content