1-8
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Connection Settings
Configuring Connection Settings
queue-limit
pkt_num
[
timeout
seconds
]
Sets the maximum number of out-of-order packets that can be
buffered and put in order for a TCP connection, between 1 and 250
packets. The default is 0, which means this setting is disabled and
the default system queue limit is used depending on the type of
traffic:
•
Connections for application inspection (the
inspect
command), IPS (the
ips
command), and TCP
check-retransmission (the TCP map
check-retransmission
command) have a queue limit of 3 packets. If the ASA
receives a TCP packet with a different window size, then the
queue limit is dynamically changed to match the advertised
setting.
•
For other TCP connections, out-of-order packets are passed
through untouched.
If you set the
queue-limit
command to be 1 or above, then the
number of out-of-order packets allowed for all TCP traffic matches
this setting. For example, for application inspection, IPS, and TCP
check-retransmission traffic, any advertised settings from TCP
packets are ignored in favor of the
queue-limit
setting. For other
TCP traffic, out-of-order packets are now buffered and put in order
instead of passed through untouched.
The
timeout
seconds
argument sets the maximum amount of time
that out-of-order packets can remain in the buffer, between 1 and
20 seconds; if they are not put in order and passed on within the
timeout period, then they are dropped. The default is 4 seconds.
You cannot change the timeout for any traffic if the
pkt_num
argument is set to 0; you need to set the
limit
to be 1 or above for
the
timeout
keyword to take effect.
reserved-bits
{
allow
|
clear
|
drop
}
Sets the action for reserved bits in the TCP header.
(Default) The
allow
keyword allows packets with the reserved bits
in the TCP header.
The
clear
keyword clears the reserved bits in the TCP header and
allows the packet.
The
drop
keyword drops the packet with the reserved bits in the
TCP header.
seq-past-window
{
allow
|
drop
}
Sets the action for packets that have past-window sequence
numbers, namely the sequence number of a received TCP packet
is greater than the right edge of the TCP receiving window.
The
allow
keyword allows packets that have past-window
sequence numbers. This action is only allowed if the
queue-limit
command is set to 0 (disabled).
(Default) The
drop
keyword drops packets that have past-window
sequence numbers.
Table 1-1
tcp-map Commands (continued)
Command
Notes
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......