Download Print this page

Cisco ASA 5506-X Configuration Manual page 274

Cli
Hide thumbs Also See for ASA 5506-X:

Advertisement

History for Connection Settings
History for Connection Settings
Feature Name
TCP state bypass
Connection timeout for all protocols
Timeout for connections using a backup static
route
Configurable timeout for PAT xlate
Increased maximum connection limits for
service policy rules
Decreased the half-closed timeout minimum
value to 30 seconds
Cisco ASA Series Firewall CLI Configuration Guide
11-18
Platform
Releases
Description
8.2(1)
This feature was introduced. The following command was
introduced: set connection advanced-options
tcp-state-bypass.
8.2(2)
The idle timeout was changed to apply to all protocols, not
just TCP.
The following command was modified: set connection
timeout
8.2(5)/8.4(2)
When multiple static routes exist to a network with different
metrics, the ASA uses the one with the best metric at the
time of connection creation. If a better route becomes
available, then this timeout lets connections be closed so a
connection can be reestablished to use the better route. The
default is 0 (the connection never times out). To take
advantage of this feature, change the timeout to a new value.
We modified the following command: timeout
floating-conn.
8.4(3)
When a PAT xlate times out (by default after 30 seconds),
and the ASA reuses the port for a new translation, some
upstream routers might reject the new connection because
the previous connection might still be open on the upstream
device. The PAT xlate timeout is now configurable, to a
value between 30 seconds and 5 minutes.
We introduced the following command: timeout pat-xlate.
This feature is not available in 8.5(1) or 8.6(1).
9.0(1)
The maximum number of connections for service policy
rules was increased from 65535 to 2000000.
We modified the following commands: set connection
conn-max, set connection embryonic-conn-max, set
connection per-client-embryonic-max, set connection
per-client-max.
9.1(2)
The half-closed timeout minimum value for both the global
timeout and connection timeout was lowered from 5
minutes to 30 seconds to provide better DoS protection.
We modified the following commands: set connection
timeout half-closed, timeout half-closed.
Chapter 11
Connection Settings

Hide quick links:

Advertisement

loading