Solved

ASA - UDP Connections Remaining Open

Posted on 2014-09-04
2
240 Views
Last Modified: 2015-02-20
Hi Guys,

We are currently having an issue where UDP Connections are not timing out specifically around our DNS calls.

We have our connection limit set to 5000 and our Internal DNS Server continues to hit this on an almost hourly basis.

When I run a "sh conn count", I can see in excess of 5,000 UDP connections from the DNS Server to servers on the web.

The CONNS-POLICY looks as follows:

policy-map CONNS-POLICY
 class CONNS-MAP
  set connection per-client-max 5000 per-client-embryonic-max 2000 
  set connection timeout idle 2:00:00 dcd 
!

Open in new window


Timeout information is as follows:

timeout xlate 3:00:00
timeout pat-xlate 0:00:30
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00

Open in new window


I am not sure how to best approach allow the DNS traffic outbound or how others have managed such an issue.

Your input would be appreciated.
0
Comment
Question by:maccadu
  • 2
2 Comments
 
LVL 61

Accepted Solution

by:
gheist earned 500 total points
ID: 40306052
But you keep STATE (*) open for 2 hours!!! Check with your DNS server defaults, but normally it stops waiting for response in 5..60s depending on its age.

(*) UDP is connectionless, ther is no connection open or closing
0
 
LVL 61

Expert Comment

by:gheist
ID: 40620711
Can you help me to understand what was wrong with my answer and DNS protocol description?
Do you have DNS responses that you get in 1-2h?
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now