Solved

Cisco anyconnect vpn protocol timeouts

Posted on 2009-07-14
2
1,179 Views
Last Modified: 2012-06-21
We have a Cisco ASA configure with Anyconnect clients connecting over ssl.

This is all working great, clients can connect and stay connected for days.

The problem we are having is that TCP sessions have an overly aggressive timeout configured.
If I log into a unix server over the vpn session using ssh, the session works fine as long as I am not idle.  If I idle the session, the ASA tears the tcp session down in around 7 minutes.  
If I have any other client/server package running that allows the session to idle for between 5 and 7 minutes, the session will die.

I assume that the ASA is tearing down TCP sessions when they time out due to excessive idle time.

I need to be able to turn this idle timer up to a much longer perion.

What configuration lines control this behavior?
0
Comment
Question by:georgew3
2 Comments
 
LVL 32

Expert Comment

by:Kamran Arshad
ID: 24857650
0
 

Accepted Solution

by:
georgew3 earned 0 total points
ID: 24947253
I found the solution.

This is the command line:

timeout conn 10:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Site-to-Site VPN Cisco ASA 5505 to Cisco RV320 4 256
Gateway Resilience 4 68
VPN Connection WIndows 10 5 78
Start Cisco VPN AnyConnect Client Before Windows Login 4 34
Preface Having the need * to contact many different companies with different infrastructures * do remote maintenance in their network required us to implement a more flexible routing solution. As RAS, PPTP, L2TP and VPN Client connections are no…
Overview Often, we set up VPN appliances where the connected clients are on a separate subnet and the company will have alternate internet connections and do not use this particular device as the gateway for certain servers or clients. In this case…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

713 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question