Re: VPN Timeout



In article <1129658274.575879.209700@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>,
gursoy <gursoy@xxxxxxxxx> wrote:
:I would like to set timeout on VPN connection on my PIX 515 firewall.
:Connections are established via Cisco VPN Client and authenticated
:through MS IAS RADIUS server.

There aren't really VPN timeouts on PIX, not quite. What you
can adjust is the isakmp policy 'lifetime' parameter. The isakmp
lifetime does not operate "since the last input": instead,
it checks back at the given interval, and if there has been *no*
traffic over the link for a -complete- interval, then it will shut
down the link (and start it up again when there is more traffic.)

You can also set connection lifetimes in general, which would affect
all connections, not just VPN; those are set through the 'timeout'
configuration commmand.
--
Programming is what happens while you're busy making other plans.
.



Relevant Pages

  • Re: PPTP Clients loose connection to cisco PIX 506E after a while..
    ... A customer of mine have just gotten a new Cisco Pix 506E, ... I've heard is that they loose connection after a while, ... pdm location 213.179.57.7 255.255.255.255 outside ... timeout xlate 0:05:00 ...
    (comp.dcom.sys.cisco)
  • PIX 515E dropping existing TCP connections
    ... I recently took over administration of a PIX 515E. ... network, and VPN to the PIX to access a private network. ... When the VPN is connected, I can SSH to hosts on the private network. ... PIX drops the connection after transferring just a few kilobytes. ...
    (comp.dcom.sys.cisco)
  • Re: RDP thru Cisco VPN client and thru 501 Failure
    ... been configured to establish a site-to-site VPN to the ... that our connection is thru his 506E, I am not sure of that. ... standard M$ connection (not requiring Cisco client) to our 501. ... Do  you have access to theofficePIX 501 and can you post the PIX 501 ...
    (comp.dcom.sys.cisco)
  • Pix 515 - upgrade from 635 to 722 - sendmail breaks
    ... Last night I installed more RAM and upgraded the PIX to 7.22. ... sendmail logs and I was receiving these messages: ... read timeout on connection from m4.campaignmonitor.com, ...
    (comp.dcom.sys.cisco)
  • Pix 515 - upgrade from 635 to 722 - sendmail breaks
    ... Last night I installed more RAM and upgraded the PIX to 7.22. ... sendmail logs and I was receiving these messages: ... read timeout on connection from m4.campaignmonitor.com, ...
    (comp.dcom.sys.cisco)