Guest

Preview Tool

Cisco Bug: CSCsy76553 - Implement a traffic threshold option in addition to the idle timeout

Last Modified

Aug 07, 2018

Products (1)

  • Cisco ASA 5500-X Series Firewalls

Known Affected Releases

8.0(4)

Description (partial)

Symptom:

Unfortunately,  the idle timeout value alone for VPN RA connections is pretty meaningless, especially with MS networking. Idle timeout does not mean the absence of application traffic, it means no traffic, period. This  includes the traffic w MS apps (networking, netbios, etc)... 

This is an enhancement request to alleviate this concerns, the ASA should have a traffic threshold option in addition to the idle timeout.  For example, if the data rate is less then 10k over idle timeout period then disconnect.

Conditions:

ASA with Anyconnect configured and IDLE-TIMEOUT configured under the group policy
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.