Configuring The Timeout For A Half-Closed Connection - Cisco 4700M Configuration Manual

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 4
Configuring TCP/IP Normalization and IP Reassembly Parameters
Note

Configuring the Timeout for a Half-Closed Connection

OL-16202-01
Configuring a Connection Parameter Map for TCP/IP Normalization and Termination
The syntax of this command is as follows:
set tcp timeout embryonic seconds
The seconds argument is an integer from 0 to 4294967295 seconds. The default is
5 seconds. A value of 0 specifies that the ACE does not time out an embryonic
connection.
This command affects only Layer 4 flows and not Layer 7 flows.
For example, enter:
host1/C1(config-parammap-conn)# set tcp timeout embryonic 24
To reset the TCP embryonic connection timeout to the default value of 5 seconds,
enter:
host1/C1(config-parammap-conn)# no set tcp timeout embryonic
A half-closed connection is a connection in which the client (or server) sends a
FIN and the server (or client) ACKs the FIN without sending a FIN itself. The
timer starts once this condition has occurred. To configure a timeout for a
half-closed connection, use the set tcp timeout half-closed command in
parameter map connection configuration mode. The syntax of this command is as
follows:
set tcp timeout half-closed seconds
The seconds argument is an integer from 0 to 4294967295 seconds. The default is
3600 seconds (1 hour). A value of 0 specifies that the ACE does not time out a
half-closed TCP connection.
For example, enter:
host1/C1(config-parammap-conn)# set tcp timeout half-closed 2400
To reset the TCP half-closed connection timeout to the default value of 3600
seconds, enter:
host1/C1(config-parammap-conn)# no set tcp timeout half-closed
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
4-15

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents