Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 301
  • Last Modified:

ASA - UDP Connections Remaining Open

Hi Guys,

We are currently having an issue where UDP Connections are not timing out specifically around our DNS calls.

We have our connection limit set to 5000 and our Internal DNS Server continues to hit this on an almost hourly basis.

When I run a "sh conn count", I can see in excess of 5,000 UDP connections from the DNS Server to servers on the web.

The CONNS-POLICY looks as follows:

policy-map CONNS-POLICY
 class CONNS-MAP
  set connection per-client-max 5000 per-client-embryonic-max 2000 
  set connection timeout idle 2:00:00 dcd 
!

Open in new window


Timeout information is as follows:

timeout xlate 3:00:00
timeout pat-xlate 0:00:30
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00

Open in new window


I am not sure how to best approach allow the DNS traffic outbound or how others have managed such an issue.

Your input would be appreciated.
0
maccadu
Asked:
maccadu
  • 2
1 Solution
 
gheistCommented:
But you keep STATE (*) open for 2 hours!!! Check with your DNS server defaults, but normally it stops waiting for response in 5..60s depending on its age.

(*) UDP is connectionless, ther is no connection open or closing
0
 
gheistCommented:
Can you help me to understand what was wrong with my answer and DNS protocol description?
Do you have DNS responses that you get in 1-2h?
0

Featured Post

Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now