FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] Cisco VPN reconnection every 23 minutes

To: "'Firewall Wizards Security Mailing List'" <firewall-wizards@listserv.cybertrust.com>, "'ditribar'" <ditribar@gmx.de>
Subject: Re: [fw-wiz] Cisco VPN reconnection every 23 minutes
From: "Andrew Bell" <andrewb@poscomp.ca>
Date: Sat, 9 Jun 2007 14:10:47 -0400
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.cybertrust.com
In-reply-to: <46644D37.8080804@gmail.com>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
Organization: Postech Computer Services
References: <OF904FA57E.B8A09523-ON862572EC.00650228-862572EC.00653F1D@fd.org><46606C2A.1090606@gmail.com> <20070602120254.263830@gmx.net> <46644D37.8080804@gmail.com>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
Thread-index: AceoUUBskkMfVrf8RKe4rd+Ol5tdQwCbvfDA
> 2007-06-01T17:40:20+0100 [...] Session disconnected. Session Type:
IPSecLAN2LAN, 
> Duration: 0h:23m:00s, Bytes xmt: 0, Bytes rcv: 2460, Reason: User
Requested

This looks like a simple inactivity timeout.  0 bytes were transmitted
through the tunnel in the 23 minutes the session was up, according to your
log, but since your group policy sets an unlimited idle timeout, and the
default for the ASA is 30 minutes anyway, I'd look at the far end idle
timeout settings.

Regards,

Andrew

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>