Cisco ASA – Configuring Connection Limits

The Cisco ASA firewall offers excellent protection for Denial of Service attacks, such as SYN floods,
TCP excessive connection attacks etc. Using the new Policy Framework functionality,
the ASA administrator can configure granular controls for TCP Connection limits and timeouts.

For example, we can control and limit the maximum number of simultaneous TCP and UDP connections
that are allowed towards a specific host (or subnet), the maximum number of simultaneous embryonic
connections allowed (for SYN flood attacks), the per-client max number of connections allowed etc.

Configuration Example

STEP1: Identify the traffic to apply connection limits using a class map

access list CONNS-ACL extended permit ip any 10.1.1.1 255.255.255.255
!
class-map CONNS-MAP
match access-list CONNS-ACL

STEP2: Add a policy map to set the actions to take on the class map traffic

policy-map CONNS-POLICY
class CONNS-MAP
set connection timeout idle 0:00:00 dcd 0:00:15 60

STEP3: Apply the Policy on one or more interfaces or Globaly

service-policy CONNS-POLICY {global | interface interface_name}( interface PUBLIC).

Additional Notes :

Default Settings :

timeout conn 2:30:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02

Modified Settings :

timeout conn 0:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02

where the embryonic hh:mm:ss keyword sets the timeout period until a TCP embryonic (half-open)
connection is closed, between 0:0:5 and 1193:00:00. The default is 0:0:30.
You can also set this value to 0, which means the connection never times out.

The idle hh:mm:ss keyword sets the idle timeout for all protocols between 0:5:0 and 1193:00:00.
The default is 1:0:0. You can also set this value to 0, which means the connection never times out.
For TCP traffic, the reset keyword sends a reset to TCP endpoints when the connection times out.

The half-closed hh:mm:ss keyword sets the idle timeout between 0:5:0 and 1193:00:00.
The default is 0:10:0. Half-closed connections are not affected by DCD. Also, the ASA does not send a
reset when taking down half-closed connections.

The dcd keyword enables DCD. DCD detects a dead connection and allows it to expire,
without expiring connections that can still handle traffic. You configure DCD when you want
idle,but valid connections to persist. After a TCP connection times out, the ASA sends DCD probes
to the end hosts to determine the validity of the connection.
If one of the end hosts fails to respond after the maximum retries are exhausted, the ASA frees
the connection. If both end hosts respond that the connection is valid, the ASA updates the activity
timeout to the current time and reschedules the idle timeout accordingly.

The retry-interval sets the time duration in hh:mm:ss format to wait after each unresponsive DCD
probe before sending another probe, between 0:0:1 and 24:0:0. The default is 0:0:15.

The max-retries sets the number of consecutive failed retries for DCD before declaring the connection
as dead. The minimum value is 1 and the maximum value is 255. The default is 5.

Where the conn-max sets the maximum number of simultaneous TCP and/or UDP connections
that are allowed, between 0 and 65535.

The embryonic-conn-max sets the maximum number of simultaneous embryonic connections
allowed, between 0 and 65535.

The per-client-embryonic-max sets the maximum number of simultaneous embryonic connections
allowed per client, between 0 and 65535.

The per-client-max sets the maximum number of simultaneous connections allowed per client,
between 0 and 65535.


set connection timeout embryonic 0:0:30 idle 0 half-closed 0:10:00 dcd 0:0:15 60

dcd : 15 secs interval and retry 60 times. 4 retries in 1 minute equals to 60 retries within 15mins.