Idle AS400 sessions drop a various time intervals. Application hangs PC... Print server needs to be restarted. TN5250 emulation. VPN tunnel stays up on 86400 second lifetime. Anybody seen something like this?
Since there has been no response to your post, it appears to be either too complex or too rare an issue for other forum members to assist you. If you don't get a suitable response to your post, you may wish to review our resources at the online Technical Assistance Center (http://www.cisco.com/tac) or speak with a TAC engineer. You can open a TAC case online at http://www.cisco.com/tac/caseopen
If anyone else in the forum has some advice, please reply to this thread.
I have the same problem with my AS400 connection through IPSEC VPN tunnels. Connections not run through the VPN (local or frame-relay) do not experience these same problems. Although the issue for me seems complicated by a GUI license manager from Seagull that uses udp to connect to the AS400. When the license manager fails to connect, it boots the user out of the AS400 application. I used a helper address and forward-protocol statements on the remote router to force these UDP packets to be forarded to the license server. Although these connections are not constant and may occur as infrequently as once an hour. What appears to happen is that either the PIX or the remote router are terminating the session through the tunnel from the client to the license server because they have been inactive for too long. When this occurs a session must be re-established and the licensing server rejects the request since it is a request from a client on a session other than that which the license was initially regestered. I notice though I do not see the same problem with my Unix telnet sessions as I and you see on those to an AS400. Although my Unix sessions are not using a GUI client. I'm almost beginning to wonder if these problems would be minimized if there were a way to force the equipment to keep inactive sessions active longer betore being closed. Although I'm not sure what the consequences of that would be on overall performance or reliability. Maybe someone here can post that info.
I believe we had a similar problem deploying VPN in Europe this year over ADSL. Our AS/400 sessions would freeze or lockup randomly. Our consultants found that the MTU size was too large to work over ADSL very well. It was reduced to about 1350 and the problem vanshed.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR
and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity
options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in
HA DocumentationCode download linksGoalRequirementLimitationsSupported
ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationCo...
Question I am currently unable to specify "crypto keyring" command when
configuring VPN connection on my cisco 2901 router. The following
licenses have been activated on my router :