Link to home
Start Free TrialLog in
Avatar of BobWoodard01
BobWoodard01

asked on

Cisco pix firewalls and Idle time out

I have a Pix 515E firewall that I am using for VPN access to the network. I have the following line in my configuration for Timeout when the user is Idle:
vpngroup Group name idle-time 1800
 This line is present but when a user connects and is idle for the alotted time they are not disconnected. Is there another command that needs to be added to acomplish this ?

Also is there a way to send a disclaimer when a user logs into the firewall using a vpn client.

Thanks for your help

Bob W
Avatar of Pete Long
Pete Long
Flag of United Kingdom of Great Britain and Northern Ireland image

how about

isakmp keepalive 30
Avatar of BobWoodard01
BobWoodard01

ASKER

I do not have that line in my configuration. Please tell me what that does.
sends a keep-alive pulse down the VPN tunnel every 30 seconds
That should keep the tunnel up, not disconnect it. Iwant the user to bedisconnected if they leave the computer for 30 minutes without doing anything.
=/ I am a clown! sorry man, a clear case of RTFQ my appols

Pete
You have the right command.  The most likely cause is that the user isn't idle.  Windows is a very chatty.  Even when you aren't doing anything the Windows OS is.  I would recommand putting an ACL on the user to block the standard chattness of windows.

--Tim
ASKER CERTIFIED SOLUTION
Avatar of Les Moore
Les Moore
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial