Reply To: Firewall / vpn timeout

Clovertech Forums Read Only Archives Cloverleaf Cloverleaf Firewall / vpn timeout Reply To: Firewall / vpn timeout

#56927
Michael Hertel
Participant

    This is from the archive:

    The author is Mike.Golovach@vtmednet.org

    If you’re on AIX, this is the solution. It sure saved me

    a lot of heartache.

    >>>>>>>>

    We had this same problem and I tried everything including letting an

    alert create a keep alive message. But the vendor would not agree to

    doing the same thing on their end of the interface for their outbound

    thread … which was a good thing. It forced me to keep digging.

    The issue was that our TCP/IP (AIX 5.2) was configured with all of the

    default timeout values. The TCP_keepidle parameter needed to be set to

    an interval shorter that Cisco timeout value. We set ours to 3600 and

    the problem was solved.

    Michael

    >>>>>>>>