service tcp-keepalives-in
service tcp-keepalives-out
ip inspect max-incomplete high 900
ip inspect max-incomplete low 800
ip inspect one-minute high 900
ip inspect one-minute low 800
ip inspect udp idle-time 10
ip inspect dns-timeout 10
ip inspect tcp idle-time 900
!
ip inspect name myfw cuseeme timeout 900
ip inspect name myfw ftp timeout 900
ip inspect name myfw rcmd timeout 900
ip inspect name myfw realaudio timeout 900
ip inspect name myfw smtp timeout 900
ip inspect name myfw tftp timeout 900
ip inspect name myfw udp timeout 10
ip inspect name myfw tcp timeout 900
ip inspect name myfw h323 timeout 900
ip inspect name myfw pptp timeout 900
ip tcp ecn
ip tcp selective-ack
ip tcp timestamp
ip tcp synwait-time 30
ip tcp path-mtu-discovery
!
int vlan 1
ip inspect myfw in
service tcp-keepalives-in :
service tcp-keepalives-out :
You can use the service tcp-keepalives-in and the service tcp-keepalives-out commands to monitor TCP connections to and from the router. They can terminate connections if the router or switch doesn’t receive a response from the remote device.
service timestamps :
You can use the service timestamps command to create timestamps on the router’s log files
service timestamps log datetime localtime msec show-timezone year
service timestamps debugging datetime localtime msec show-timezone year
ip tcp ecn :
The TCP Explicit Congestion Notification (ECN) feature provides a method for an intermediate router to notify the end hosts of impending network congestion. It also provides enhanced support for TCP sessions associated with applications that are sensitive to delay or packet loss including Telnet, web browsing, and transfer of audio and video data. The benefit of this feature is the reduction of delay and packet loss in data transmissions.
ip tcp timestamp :
The timestamp option lets the sender place a timestamp value in every segment. The receiver reflects this value in the acknowledgment, allowing the sender to calculate an RTT for each received ACK.
TCP time stamp improves round-trip time estimates
ip tcp selective-ack :
TCP might not experience optimal performance if multiple packets are lost from one window of data. With the limited information available from cumulative acknowledgments, a TCP sender can learn about only one lost packet per round-trip time. An aggressive sender could resend packets early, but such re-sent segments might have already been received.
The TCP selective acknowledgment mechanism helps overcome these limitations. The receiving TCP returns selective acknowledgment packets to the sender, informing the sender about data that has been received. The sender can then resend only the missing data segments.
TCP selective acknowledgment improves overall performance. The feature is used only when a multiple number of packets drop from a TCP window. There is no performance impact when the feature is enabled but not used.
This command becomes effective only on new TCP connections opened after the feature is enabled.
ip tcp synwait-time :
Set a period of time the Cisco IOS software waits while attempting to establish a TCP connection before it times out