Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

Security Tidy up

service tcp-keepalives-in

service tcp-keepalives-out

These 2 commands above

SHold I configire them on our routers. Reading the explanation, it seems as if it will keep connection open so why should i configure them on the rotuer?

Or should I do a

no service tcp-keepalives-in

no service tcp-keepalives-out

Thanks

1 REPLY
Hall of Fame Super Silver

Re: Security Tidy up

adetutu

My experience with those two commands is that they are helpful. I am not sure which explanation you saw or how you interpret it but my experience is that sometimes the peer of a TCP connection becomes unresponsive. Normally the TCP connection may stay up for a while even if the other end of the session is unresponsive. the tcp-keepalive will help to detect this condition and terminate the connection more quickly. So my experience is not that it keeps it open longer but that it may close it more quickly. So I would suggest that you enable these commands.

HTH

Rick

136
Views
0
Helpful
1
Replies
CreatePlease to create content