BobWoodard01
asked on
Cisco pix firewalls and Idle time out
I have a Pix 515E firewall that I am using for VPN access to the network. I have the following line in my configuration for Timeout when the user is Idle:
vpngroup Group name idle-time 1800
This line is present but when a user connects and is idle for the alotted time they are not disconnected. Is there another command that needs to be added to acomplish this ?
Also is there a way to send a disclaimer when a user logs into the firewall using a vpn client.
Thanks for your help
Bob W
vpngroup Group name idle-time 1800
This line is present but when a user connects and is idle for the alotted time they are not disconnected. Is there another command that needs to be added to acomplish this ?
Also is there a way to send a disclaimer when a user logs into the firewall using a vpn client.
Thanks for your help
Bob W
ASKER
I do not have that line in my configuration. Please tell me what that does.
sends a keep-alive pulse down the VPN tunnel every 30 seconds
ASKER
That should keep the tunnel up, not disconnect it. Iwant the user to bedisconnected if they leave the computer for 30 minutes without doing anything.
=/ I am a clown! sorry man, a clear case of RTFQ my appols
Pete
Pete
You have the right command. The most likely cause is that the user isn't idle. Windows is a very chatty. Even when you aren't doing anything the Windows OS is. I would recommand putting an ACL on the user to block the standard chattness of windows.
--Tim
--Tim
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
isakmp keepalive 30